I was asked to participate in a Q&A session late last year, focusing on what the new year holds for us. It was the season for this type of activity, along with goal settings and …


Introduction An information security policy is a fundamental element of protecting information assets. It would not be an exaggeration to say that an effective information security framework starts and finishes with a well-defined and well … Continue reading On policy/standard development


This is an Accepted Manuscript of the article published by Taylor & Francis in EDPACS , Volume 57 Issue 2, available online: /doi.org/10.1080/07366981.2018.1426929.       Abstract GDPR is not an easy read, so most …


"Information Security is only as strong as the weakest link in the chain" The above statement seems to be popular. It appears time to time in blogs, on company websites, in research, in white papers, …

"…I think that the minute that you have a backup plan, you've admitted that you're not going to succeed…" The above quote was making its rounds on LinkedIn for a while. People "liked" it. Many …

On frameworks – how to choose one?

I was approached by a number of people recently, asking my opinion on frameworks. TOGAF, SABSA, COBIT 5, CMMI, and the list go on. Their roles include CISO, security engineer, consultant and so on. A …