Articles tagged with: risk management

How to prepare your organisation for ISO 27001?

How to Prepare your Organisation For

How to prepare your organisation for ISO 27001?

Preparation, skills and decision-making ahead of the next course.

⏱️ Estimated reading time: 8–9 minutes

Preparing for ISO 27001 in Portugal becomes urgent when external or internal demands arise. The main factors that accelerate this process include requests from clients for evidence, specific requirements in commercial proposals, upcoming audits, or management’s need to assess risk exposure. In these urgent situations, the scope, allocation of responsibilities, selection of controls and validation of skills tend to be decided under considerable pressure.

NIS2 and ISO/IEC 27001: the same obligation or two different requirements?

Cybersecurity obligations and requirements

NIS2 and ISO/IEC 27001: the same obligation or two different requirements?

NIS2 and ISO/IEC 27001 share a common vocabulary: risk, controls, incidents, responsibilities. But they do not have the same nature or the same purpose. Treating one as a substitute for the other is one of the most frequent misunderstandings, with practical consequences for organisations and professionals.

⏱️ Estimated reading time: 6 minutes

The entry into force of NIS2 reinforced an idea that many organisations already knew, but did not always treat with the necessary priority: cybersecurity is no longer merely a technical concern and has become a requirement of governance, risk management, operational continuity and management accountability.At the same time, many entities already had, or are preparing, information security management systems based on ISO/IEC 27001. This raises a frequent question:Is complying with ISO/IEC 27001 the same as complying with NIS2?The answer is clear: no. NIS2 and ISO/IEC 27001 are not the same obligation. But they are deeply related.

Change management in information systems: a business continuity risk that cannot be ignored

Managing_Changes

Change management in information systems: a business continuity risk that cannot be ignored

Change management in information systems is not just a technical issue. When a change may affect critical processes, services, data, suppliers or operational capacity, it must also be analysed as a business continuity risk.

⏱️ Estimated reading time: 6 minutes

Some questions seem technical, but reveal a much broader concern.
One of them is this: “Is there any training course on change management in information systems?” The answer is yes. But the most important part of the answer is not only the name of the training course. It lies in understanding what this question really means.