# Turning a standard into technical alerts

Security galaxy · Cédric Merlin, CTO · https://merlin-cedric.fr/en/securite/conformite/

Each requirement of a standard (ISO 27001, ISO 27005, PCI DSS) becomes a technical control, then an alert.

## The problem

ISO 27001 or NIS2 are scary because they feel like paperwork.

## What I did

1. **A requirement.** I start from a requirement of the standard.
2. **A technical control.** I choose the technical control that meets it.
3. **An alert.** I set up the alert that warns me when it no longer holds (for example with an open source SOC).

## The result

ISO 27001 and PCI DSS requirements turned into technical controls, with an alert when a control fails.

Figure: 3 standards turned into technical controls.

## Certifications

CKA, PCI DSS, ISO 27001, CEH, LPIC-1, CCNA. French Confidentiel Défense security clearance.

---
Page: https://merlin-cedric.fr/en/securite/conformite/ · Contact: contact@merlin-cedric.fr
