There aren't many certifications (or any) where passwords are all required to be rotated every 60 days. Heck, NIST even changed their guidance on this to be more nuanced. As an information security auditor I certainly don't recommend people change passwords on a set basis, we used to but the thought process has completely changed.
But I appreciate that the password example wasn't the point of your comment. Organisations will often default to a certification and/or standard blindly because they don't have the knowledge of how to do it differently themselves, or they don't want to be on the hook for choosing to deviate from a standard and be bitten.
Realistically security teams should be able to go above and beyond the strength of these certifications. In any case, ISO 27001 isn't really that great of a cert, it is only smaller less mature organisations that flash ISO 27001 as anything worth seeing.
Comments
There aren't many certifications (or any) where passwords are all required to be rotated every 60 days. Heck, NIST even changed their guidance on this to be more nuanced. As an information security auditor I certainly don't recommend people change passwords on a set basis, we used to but the thought process has completely changed.
But I appreciate that the password example wasn't the point of your comment. Organisations will often default to a certification and/or standard blindly because they don't have the knowledge of how to do it differently themselves, or they don't want to be on the hook for choosing to deviate from a standard and be bitten.
Realistically security teams should be able to go above and beyond the strength of these certifications. In any case, ISO 27001 isn't really that great of a cert, it is only smaller less mature organisations that flash ISO 27001 as anything worth seeing.
Spot on at the end there