InfoSec Insider

URM Consulting

The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.

  1. 2 gg fa

    PCI DSS and Severless Architecture

    In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore the use of severless architecture and Payment Card Industry Data Security Standard (PCI DSS) compliance.  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:     What ‘severless’ actually means in a PCI DSS context, and how this differs from how it is usually described by cloud providers What QSAs look for when deciding whether a severless system falls within PCI scope How the balance of responsibilities shifts when an organisation moves from traditional cloud services to severless, and where this causes the most confusion during assessments The parts of a severless setup that tend to bring cardholder data into scope unexpectedly and how to ensure you understand the way information moves through your systems How to handle PCI requirements for logs, monitoring and keeping evidence when the systems they rely on disappear almost instantly Maintaining compliant access control and control over changes to your systems in a severless context How to check for weaknesses in severless systems, the risks tied to the external code and libraries that are often used inside serverless functions And more. Ask Alastair and Tibor a question:  https://www.urmconsulting.com/podcasts/pci-dss-and-severless-architecture If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider         You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts        Connect with us on LinkedIn   Brought to you by URM, the UK’s leading information and cyber security specialists.

    25 min
  2. 14 mag

    AI Supplier Management

    In this episode of InfoSec Insider, Jack Woods and George Ryan, both Consultants at URM, share their insights on how organisations can effectively manage AI suppliers and navigate the emerging risks associated with artificial intelligence in the supply chain. Jack and George draw on their experience supporting organisations with AI governance and supplier risk management to discuss: What AI supplier management is and how it differs from traditional supplier management, including the impact of rapidly evolving AI models and changing service structures The key risks associated with AI suppliers, such as data leakage, unauthorised model training, hallucinations, bias, and compliance challenges The growing issue of shadow AI, and how a lack of visibility over employee use of AI tools can introduce significant security and governance risks How organisations can adapt due diligence processes to assess AI suppliers, including evaluating data handling practices, model governance, human oversight, and security maturity Contractual and governance considerations, such as restricting data use, ensuring transparency on model updates, and defining audit and incident response expectations The importance of understanding extended AI supply chains, including dependencies on underlying models and fourth-party providers Why AI supplier management must be treated as an ongoing activity, with continuous monitoring, internal communication, and reassessment of risk as technologies evolve Ask Jack and George a question: https://www.urmconsulting.com/podcasts/aI-supplier-management   If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider             You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts             Brought to you by URM, the UK’s leading information and cyber security specialists.

    22 min

Descrizione

The InfoSec Insider podcast brings you weekly interviews with practicing senior consultants, who draw upon their extensive experience to provide detailed and practical guidance on all things information and cyber security, data protection compliance, risk management, and more. In each episode, one of our experts takes a deep-dive into a particular aspect of their area of specialism, whether that be certifying to ISO 27001, outlining some top tips for GDPR compliance, making the case for alternative approaches to pen testing, or discussing how to conduct an effective business impact analysis (BIA). Enhance your understanding and professional skillset with the InfoSec Insider podcast, brought to you by URM, the UK’s leading provider of cyber security and governance, risk management and compliance consultancy.

Potrebbero piacerti anche…