Blog
Recent blogs

ISO 27001 Clause 4.1 - Understanding the Organisation and its Context
Published on
21
September
2026
TRENDING
URM's blog explores ISO 27001 Clause 4.1 & how to identify organisational context, assess internal/external issues, and support effective ISMS decision-making.
Read more
Information Security
Published on
5/8/2022
PCI DSS – The Payment Card Data Security Standard – What is it?TRENDING
Often referred to as the PCI DSS or quite simply PCI, the Standard was developed by the founding payment brands....
Information Security
Published on
5/8/2022
PCI DSS Reduction and AssessmentTRENDING
The Payment Card Industry Security Standards Council (PCI SSC) defines scoping as “the process of identifying all system components....
Information Security
Published on
4/8/2022
PCI DSS Remediation and ImplementationTRENDING
PCI remediation is an essential activity for any organisation wishing to fully comply.....
Information Security
Published on
4/8/2022
PCI DSS Gap AnalysisTRENDING
URM’s PCI DSS gap analysis service is aimed at those organisations which are looking to benchmark....
Information Security
Published on
27/7/2022
How Secure is Zoom?TRENDING
Many organisations have had to adapt very quickly to the rapidly changing restrictions brought in across the globe to help combat the spread of COVID-19.
Information Security
Published on
27/7/2022
Risk Management – What is it and What Role Does it Play in ISO 27001?TRENDING
We are going to explore why the focus on a risk-based approach has helped turn ISO 27001, the International ISM Standard, into such a world-beater.
Information Security
Published on
27/7/2022
How to Improve Your Password ManagementTRENDING
One of the long-held beliefs underpinning many a password policy is that forcing a regular password change is a good thing.
Information Security
Published on
27/7/2022
Difference Between Certified and Compliant ISO 27001 ISMSTRENDING
There is some confusion about the difference between having an ISMS which is certified to ISO 27001 and one which is compliant or aligned to the Standard.
Information Security
Published on
27/7/2022
What are the Basics of Internal Auditing?TRENDING
With this blog, the spotlight turns to internal audit and specifically in the context of ISO 27001, the International Standard for ISM.
Information Security
Published on
27/7/2022
How do You Avoid Information Security Breaches?TRENDING
With the news often including stories regarding high-profile information security breaches, many of us find ourselves asking how we can avoid it.
Information Security
Published on
27/7/2022
How Should You Onboard New IT Systems and Software? TRENDING
This blog takes a look at onboarding information systems. When onboarding is mentioned will conclude it’s referring to people but there is a lot more to think
Information Security
Published on
27/7/2022
How Do You Go About Your ISO 27001 Information Classification?TRENDING
This blog talks about information classification. So, what exactly do we mean by information classification?
Information Security
Published on
27/7/2022
What is the Difference Between IT and Information Governance?TRENDING
In this blog, we are going to look at governance. We are regularly asked, ‘is information governance the same as IT governance?’
Information Security
Published on
27/7/2022
How do You Identify and Then Manage Your ISMS Scope?TRENDING
When managing the security of your organisation’s information assets, you will need to consider the scope of what you are doing.
Information Security
Published on
27/7/2022
Should You Start Your ISO 27001 Programme with a Gap Analysis or a Risk Assessment?TRENDING
The answer depends on your goals and knowledge of your current position. This blog will look at which is best and when.
Data Protection
Published on
25/7/2022
How to Respond to a Data Subject Access Request (DSAR)TRENDING
Let’s face it, there is nothing straightforward or simple about responding to a data subject access request (DSAR).
Data Protection
Published on
25/7/2022
What is the UK International Data Transfer Agreement and What Are the Implications?TRENDING
On 2 February 2022, the Information Commissioner’s Office (ICO) laid before Parliament changes around restricted international personal data transfers.
Data Protection
Published on
25/7/2022
Data Subject Access Requests (DSARs) ServicesTRENDING
One of the fundamental rights of an individual (data subject), under the UK GDPR is to be able to access and receive a copy of their personal information.
Data Protection
Published on
25/7/2022
Data Transfer Risk AssessmentTRENDING
We are focussing on transfer risk assessments (TRAs), commencing with the background that led to their introduction and then addressing the five questions.
Data Protection
Published on
25/7/2022
What is the GDPR?TRENDING
The GDPR (EU) 2016/679 is an EU regulation which came into effect on 25 May 2018 and set a new benchmark for the processing of personal data.
Data Protection
Published on
25/7/2022
The CJEU Declares the EU-US Privacy Shield Invalid and SCCs ValidTRENDING
On 16 July 2020, the CJEU issued its judgement on the adequacy of both the Privacy Shield and standard contract clauses (SCCs).
Data Protection
Published on
25/7/2022
What is the Purpose of ISO 27701 and What Benefits Does it Bring?TRENDING
The need for guidance on how organisations should best protect privacy and manage personal information has never been more pertinent.
Data Protection
Published on
25/7/2022
ISO 27701:2019 and the GDPRTRENDING
The EU GDPR and the UK DPA both require organisations to protect and ensure the privacy of any personal data which they process.
Data Protection
Published on
25/7/2022
In-house Resource vs Virtual DPOTRENDING
This blog takes a look at DPOs and considers when to look in-house and when a virtual, external resource or hybrid resource may be a better option.
Data Protection
Published on
25/7/2022
Data Subject Access Requests (DSARs) – The Need for Education and Centralised ProcessesTRENDING
We discuss the importance of ensuring that your whole organisation can identify a DSAR and the benefits of controlling the entry points of DSARs.
Data Protection
Published on
22/7/2022
Verifying the Identity of Someone Requesting Information Under the GDPR TRENDING
We look at the requirement within both the DPA and the GDPR to verify the identity of an individual making a request before acting or releasing information
Data Protection
Published on
22/7/2022
Data Protection and Management System Standards – Which is Best for Me?TRENDING
Is there a catch-all international standard that effectively proves external verification of data protection compliance?
Data Protection
Published on
22/7/2022
Transferring Personal Data Outside of the EEATRENDING
This blog looks at a very specific area of the GDPR - Article 28 and data transfer outside of the EEA.
Data Protection
Published on
22/7/2022
Supply Chain Compliance with the GDPRTRENDING
This blog focuses on an aspect of the GDPR which can be particularly challenging for a number of organisations.
Data Protection
Published on
22/7/2022
What is the Difference Between Personal Data and Sensitive Personal Data?TRENDING
There is some confusion about the difference between personal data and sensitive personal data and even whether sensitive personal data exists as a term!
URM regularly holds FREE seminars and webinars. Check out upcoming events.
Find out more
how URM CAN HELP?
URM CONSULTING services
Unsure how to approach ISO 42001 or AI governance more broadly?
You do not need a fully defined programme to speak with us. We offer a free, no‑obligation call to help you understand ISO 42001 requirements, assess your current AI governance maturity, and identify practical next steps.
Read more
URM CONSULTING services
Unsure how PCI DSS applies to your environment?
You do not need a fully scoped programme to speak with us. We offer a free call to help you understand your PCI DSS obligations, clarify scope, and identify practical next steps. Early insight can significantly reduce complexity and cost
Read more
URM CONSULTING services
SOC 2 preparation is easier with the right guidance early on
A short, free, non‑commitment call can help you confirm scope, prioritise remediation efforts, and plan your assessment with confidence. Speaking with us early often saves time and avoids common pitfalls during the audit process.
Read more
"
Our experience with URM was all around great and seamless, starting with our account manager who organised everything and was very accommodating, working around our schedule and fitting us in as soon as we wanted. This continued with our assessor for the CE questionnaire part; he was very helpful, taking the time to explain some aspects that were a bit unclear to me and guiding me the whole way through. The same was true of our assessor for the CE+, who took the time to answer any questions I had beforehand and guide me through elements that I was unfamiliar with. During the assessment, he was very helpful, made the process very easy and guided me through some points that needed some additional set up in order to ensure a successful process. This was our first year working with URM and I am sure we’ll be talking again next year. Thank you for all your help!
contact US
Let us help you
Let us help you in your compliance journey by completing the form and letting us know how we can best support you.
