u/KristenssonAB

How do you handle the overlap between NIS2, GDPR and ISO 27001?

Many Swedish organisations currently need to work with several sets of requirements at the same time. It's easy to end up creating a separate project, a separate checklist and new governance documents for each regulation.

At the same time, many areas overlap, for example risk management, incident management, supplier governance, accountability and documentation.

One alternative is to first establish a common control structure, and then map each requirement to existing processes, controls and responsibilities.

How do you work with this? Do you have a shared governance model, or do you handle each regulation separately? Which parts have been hardest to align?

reddit.com
u/KristenssonAB — 2 days ago

What is your best practical tip for NIS2, ISO 27001, GDPR or GRC work?

Ahead of the autumn, we're curious to hear practical experiences from organisations working with the Cybersecurity Act (NIS2), ISO 27001, GDPR, GRC or similar requirements.

What has made the biggest difference for you?

Examples:

  • a better current-state assessment,
  • clearer risk ownership,
  • simpler governance documents,
  • stronger management buy-in,
  • external advisory support,
  • technical verification,
  • a clearer CISO/GRC role,
  • better follow-up on remediation actions.

What is your best practical tip?

reddit.com
u/KristenssonAB — 5 days ago
▲ 3 r/grc

CRA in practice: how are you preparing security requirements in product development?

The Cyber Resilience Act covers products with digital elements - software and connected products sold in the EU. The big compliance deadlines are still a way off, but a lot of organizations are already having to bake security requirements into their dev process now.

Curious how others are actually tackling this:
Have you started tying security requirements, vulnerability handling, patching, and risk assessment into the product lifecycle?

And what's the hardest part to nail down - the tech itself, the process, who's accountable, the documentation, interpreting the legal text, or the supply chain?

reddit.com
u/KristenssonAB — 9 days ago