ISO 28000: Your Resilience, Their Budget

ISO 28000: Your Resilience, Their Budget

In this episode of the ITSM Practice Podcast, Luigi Ferri explores why supply chain resilience has become one of the biggest strategic challenges for Government Managed Service Providers (MSPs). Using practical examples from healthcare and public services, he explains how ISO 28000 shifts the conversation from protecting internal systems to managing the security and resilience of the organizations you depend on. Discover why supplier failures, inherited risk, and third-party dependencies are becoming the greatest threats to service continuity, cybersecurity, and operational resilience in government and regulated industries.


In this episode, we answer:

Why is ISO 28000 becoming essential for Government Managed Service Providers and supply chain resilience?

How can third-party suppliers and subcontractors become the weakest link in your cybersecurity and operational resilience strategy?

Why should CISOs focus on inherited risk and supplier dependencies rather than only internal security controls?


Resources Mentioned in this Episode:

The Standards Institution of Israel website, article "SI ISO 28000 :2022 Specification for security management systems for the supply chain", link https://www.sii.org.il/en/iso-28000


ANSI website, article "What Is ISO 28000?", link https://blog.ansi.org/anab/what-is-iso-28000/


Wikipedia website, article "ISO 28000", link https://en.wikipedia.org/wiki/ISO/PAS_28000


NIST website, publication "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations", link https://csrc.nist.rip/Pubs/sp/800/161/r1/2PD


SITS website, article "NIS2, DORA & Co: Aren’t we all part of someone’s relevant supply chain?", link https://sits.com/en/blog/nis2-dora-supply-chain/


UK Government website, notice "Research on cyber security in supplier management and procurement", link https://www.gov.uk/government/publications/research-on-cyber-security-in-supplier-management-and-procurement


Connect with me on:

LinkedIn: https://www.linkedin.com/in/theitsmpractice/

Website: http://www.theitsmpractice.com

And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.


Credits:

Sound engineering by Alan Southgate - http://alsouthgate.co.uk/


Graphics by Yulia Kolodyazhnaya

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(165)

Should Your CMDB Know Your Business Risk?

Should Your CMDB Know Your Business Risk?

A critical vulnerability is not automatically a critical business risk. If your CMDB only tells you which server is affected but not the customer, service, contract, SLA, or revenue behind it, you are...

22 Sep 19min

Is Your Security Stack Too Big?

Is Your Security Stack Too Big?

Is your security stack actually protecting you, or are you just paying for too many tools? This episode looks at security tool sprawl, unused capabilities, overlapping products, skills gaps and vendor...

15 Sep 13min

24/7 IT Support: Why Coverage Is Not Capability

24/7 IT Support: Why Coverage Is Not Capability

24/7 support does not automatically mean 24/7 capability. In this episode of The ITSM Practice Podcast, Luigi Ferri explores how MSPs can design profitable 24/7 IT support using follow-the-sun models,...

8 Sep 11min

The Last Human-Only Leadership Generation: How AI Is Transforming the Workforce

The Last Human-Only Leadership Generation: How AI Is Transforming the Workforce

AI is no longer just a technology tool, it is becoming part of the workforce. In this episode, Luigi Ferri explores why AI represents a workforce transformation rather than a technology project, and h...

1 Sep 11min

ENISA Cyber Exercises: Why Testing Cybersecurity Isn't Enough

ENISA Cyber Exercises: Why Testing Cybersecurity Isn't Enough

Are cyber exercises actually improving your cybersecurity resilience, or just satisfying compliance requirements? In this episode, Luigi Ferri explores ENISA's cyber exercise methodology, the gap betw...

25 Aug 8min

Projects Deliver Outputs. Services Deliver Outcomes.

Projects Deliver Outputs. Services Deliver Outcomes.

Projects Deliver Outputs, Services Deliver Outcomes: The Ownership Crisis Nobody Discusses. Discover why the biggest risk in any IT project begins after go-live. In this episode, Luigi Ferri explores ...

18 Aug 11min

MSPs: Your AI Contracts Are Obsolete

MSPs: Your AI Contracts Are Obsolete

AI is transforming Managed Service Providers (MSPs) from managing technology to managing AI behavior. This episode explains why traditional service design, governance, contracts, and risk models are n...

11 Aug 16min

DARE25: Why Defense Isn't Enough

DARE25: Why Defense Isn't Enough

Discover why traditional cybersecurity defense is no longer enough in the AI era. Luigi Ferri explores the DARE25 framework, dynamic risk management, governance, Purple Teaming, accountability, and ad...

4 Aug 9min

Populært innen Teknologi

teknisk-sett
tomprat-med-gunnar-tjomlid
lydartikler-fra-aftenposten
energi-og-klima
elektropodden
rss-ki-praten
hans-petter-og-co
nasjonal-sikkerhetsmyndighet-nsm
shifter
smart-forklart
rss-alt-som-gar-pa-strom
rss-ai-forklart
teknologi-og-mennesker
rss-snakk-om-sikkerhet
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
fornybaren
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
pedagogisk-intelligens
rss-alt-vi-kan
rss-heis