Blog tagged as GRC

The information security risk management according to the ISO 27005 standard
The ISO/IEC 27005:2022 provides a useful guidance on «risk management of the information security» for every kind of organization: read more on our blog!
itSMF Staff
15 Apr 2025 09:43 AM - Comment(s)
The management systems for artificial intelligence ISO 42001:2023 and risk treatment according the Annex A
The ISO 42001:2023 standard Annex A provides a series of objective controls and operational controls that organizations can apply to address risks related to AI systems.
itSMF Staff
19 Mar 2025 07:00 AM - Comment(s)
La resilienza aziendale: esempi pratici di attività ricorrenti e manutenzioni essenziali
In questo ultimo post dedicato alla resilienza aziendale, scopriamo una serie di esempi pratici di attività ricorrenti e manutenzioni essenziali.
itSMF Staff
03 Mar 2025 12:05 PM - Comment(s)
Understanding AI terms and definitions according to the standard ISO 22989
The ISO 22989 standard on «information technology — artificial intelligence — artificial intelligence concepts and terminology» provides concepts and terminology to improve the understanding of AI.
itSMF Staff
19 Feb 2025 07:00 AM - Comment(s)
Come costruire la resilienza aziendale fuori e dentro l'area ICT
Scopriamo insieme come costruire la resilienza aziendale fuori e dentro l'area ICT: dalle pratiche chiave alle macroaree che sono considerate per l'implementazione.
itSMF Staff
05 Feb 2025 07:00 AM - Comment(s)
The AI governance and the main related ISO standards: 42001, 38507 and 38500
Organizations that need to adopt an effective artificial intelligence governance approach can find useful guidelines in the ISO/IEC 38507:2022 (and its main related standards).
itSMF Staff
22 Jan 2025 07:00 AM - Comment(s)
La resilienza aziendale: che cos'è, perché è indispensabile e come implementarla
Scopriamo insieme qual è il significato di resilienza aziendale, perché è indispensabile per ogni organizzazione e come possiamo implementarla.
itSMF Staff
08 Jan 2025 06:00 AM - Comment(s)
Medical devices and health software: a closer look to the related ISO standards
Let's check out how the implementation of technological solutions in the health industry brings the need of protection and security of data and which ISO standards can help to manage them.
itSMF Staff
09 Dec 2024 10:35 PM - Comment(s)
The ICT consultancy service management according to the ISO 20700 standard
The ISO 20700:2017 on guidelines for management consultancy services provides a useful framework for ICT consultancy services.
itSMF Staff
02 Oct 2024 07:00 AM - Comment(s)
The medical devices data protection compliance: EU Regulation 745/2017, GDPR and ISO 27001
Let's check out our approach to the medical devices data protection compliance between EU and Switzerland according to EU Regulation 745/2017, GDPR, FADP and ISO 27001.
itSMF Staff
02 Jul 2024 10:09 AM - Comment(s)
The EU Network & Information Security 2 (NIS 2) Directive: a GRC approach with the main related ISO standards
The Network & Information Security 2 EU Directive set a new high common level of cybersecurity across the Union: let's check out more details about it.
itSMF Staff
22 May 2024 06:08 PM - Comment(s)
The EU Regulation on Digital Operational Resilience Act (DORA): GRC approach and main related standards
The Digital Operational Resilience ACT (EU Regulation 2022/2554) entered into force con January 2023: let's check out all its novelties.
itSMF Staff
24 Apr 2024 07:00 AM - Comment(s)
The Central Bank of Bahrain requirements for ICT resource in financial sector: GRC approach and main related standards.
The Central Bank of Bahrain defined in its rulebook the requirements to the ICT resources management in the financial sector: let's check them out!
itSMF Staff
02 Apr 2024 02:31 PM - Comment(s)
The management systems for artificial intelligence according to ISO 42001:2023
The ISO 42001:2023 standard provides the requirements for implementing an artificial intelligence management system within organizations that provide AI-based products or services.
itSMF Staff
06 Mar 2024 02:25 PM - Comment(s)
Information Security Incident Management according to the ISO/IEC 27035-2 standard
The ISO/IEC27035-2:2016 standard provides guidelines to plan and prepare for incident response and to learn lessons from incident response.
Davide Micheli
28 Jun 2023 07:00 AM - Comment(s)
Information Security Incident Management according to the ISO/IEC 27035-1 standard
The ISO/IEC27035-1:2016 standard provides useful principles for handling information security incidents: let's check them out in our post.
Davide Micheli
03 May 2023 07:00 AM - Comment(s)
Information technology and information security integration according to the ISO/IEC 27013:2021 standard
Information technology and information security can be integrated according to the ISO27013: let's take a closer look at this standard.
Davide Micheli
22 Feb 2023 09:07 AM - Comment(s)
Privacy & Risk Management according to ISO/IEC 27557:2022
The ISO/IEC 27557:2022 standard on information security, cybersecurity and privacy protection offers us a framework for assessing the organizational privacy risk.
Davide Micheli
08 Feb 2023 07:00 AM - Comment(s)
GRC and Artificial Intelligence: a scenario
Artificial Intelligence is getting day after day more important for a lot of human activities: AI can add a lot of value also on the adoption of a smart GRC model for our business.
Davide Micheli
13 Dec 2022 12:19 PM - Comment(s)
The integrated ICT GRC in Swiss and Italian financial services industry
Financial services industry in Italy and Switzerland can take advantage of an integrated management of ICT GRC: let's take a look at our approach.
Davide Micheli
19 Oct 2022 09:24 AM - Comment(s)