Hacker News new | past | comments | ask | show | jobs | submit login

For ISO 27001:

- Two-factor authentication (2FA) - Not stipulated - Access control for any accounts that store sensitive information - Access control policy is required - End-to-end encryption - Not stipulated - Training staff in data protection awareness, and a data privacy policy - Training policy is required

For the controls not stipulated in the standard (e.g. 2FA, E2E encryption), you may find you ultimately need them once you do an information risk assessment. As long as you explain clearly why the risk is not significant enough to require it or have good alternate controls, you won't get dinged by the auditor for not having these.




Right, but the original article is talking about GDPR. There is nothing in GDPR that says "you need to use MFA".




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: