Cyber Sec Panel – ISO Annual Meeting

Cyber Sec Panel – ISO Annual Meeting

This past week I was able to attend my first ISO Annual Meeting being hosted by AFNOR in Paris, France. This is not an event I usually attend but I was asked to sit on a panel to provide a cybersecurity and standardization perspective.

It was both exciting and humbled to be asked to do this. Given I am an International Convenor for a working group within SC 27 and the national chair for the mirror committee to ISO/IEC SC 27 in Canada it provides me the ability to share experiences and approaches for both creating and implementing international standards for businesses and governments.

The focus of my comments was around how local views can be limiter especially when just chasing compliance targets. While helpful, compliance programs are basic level needs and are not built on risk based approaches but meeting a specific focused target. Many SMBs globally are struggling to understand how cyber security is impacting their businesses and stuck in the realization that the current situation is only for new threats is increasing. Hallway discussions with delegates this become abundantly clear and I hope this conversation, while only a starting point is a beginning.

As we are working towards a SMB Guide for ISO 27001 (currently in PWI stage) we acknowledge the market need and are working towards providing the guidance. Specific to my Working Group (WG 4 under ISO/IEC SC 27) we have several PWIs looking at AI from code generation, use of LLMs, and now agents. However this is not all, we are revamping our standards on secure software with a PWI so I hope to be able to share more in the future once this has been solidified. We have a great upcoming ISO lead editor in Matt Houseman leading these discussions.

Speaking of AI, it was entertaining to watch the AI interpretation of the global speakers. While this technology has come so far using LLMs and models on native English speakers on a global stage it demonstrates its clear limitations and how the tech bros focused on using Caucasian first nation countries to develop their models. Small but very significant impact for all countries attempting to use these technologies.

In closing, I want to thank the team at AFNOR and ISO for considering me for this panel and also to the Standards Council of Canada for supporting me to attend this event. I am grateful for this opportunity and hope my insight is helpful for anyone looking to improve their security posture globally.

Once available I will share the ISO links to these meetings.

SC 27 Free Resources: https://committee.iso.org/sites/jtc1sc27/home/wg2.html