← SecurityCédric MerlinFREN

Security galaxy Case 5 of 5

Turning a standard into technical alerts

The problem

ISO 27001 or NIS2 are scary because they feel like paperwork.

What I did

01

A requirement

I start from a requirement of the standard.

02

A technical control

I choose the technical control that meets it.

03

An alert

I set up the alert that warns me when it no longer holds (for example with an open source SOC).

Diagram: from requirement to alertA line of the standard’s text is highlighted. It becomes a firewall rule, “deny by default”, inside a shield. When that rule is switched off, a bell rings: it is the SOC alert.requirementdeny bydefaultcontrolopen source SOCalert

The result

ISO 27001 and PCI DSS requirements turned into technical controls, with an alert when a control fails.

3 standards

turned into technical controls

Certifications

CKA, PCI DSS, ISO 27001, CEH, LPIC-1, CCNA. French Confidentiel Défense security clearance.