顯示包含「ISO 27001」標籤的文章。顯示所有文章
顯示包含「ISO 27001」標籤的文章。顯示所有文章

2025年11月6日星期四

Cyber Security Summit Hong Kong 2025

I on behalf of Hong Kong Society for Quality (HKSQ) attended the Cyber Security (CS) Summit Hong Kong 2025 on 6th Nov 2025. I took a photo in front of banner for memory.


I met my brother Mr. Philip Lai (Solution Director, Hong Kong Enterprise Network Solution Sales Department, Huawei) who is one of keynotes in the summit.


I also met my colleague Prof. Allen Au (Professor, COMP, PolyU).


We recognized a new friend Mr. Jonathan Fong (Deputy Managing Director, Hip Shing Hong (Holdings) Co., Ltd.) who represented the Hong Kong General Chamber of Commerce (HKGCC).


Two new friends I met were Ms. Maggie Yuen (Marketing Manager, ISC2) and Mr. Keith Li (Chairman, Hong Kong Wireless Technology Industry Association (WTIA)).


HKSQ seat location assigned.


In the beginning, Mr Emil YU Chen-on (Deputy Chairman, HKPC) gave welcome speech.


Then all the guests began the ceremony.


The committee members took a group photo.


And then supporting organizations took a group photo where HKSQ and COMP, PolyU as well as other association representatives joined together.


The first keynote speaker was Ir Tony WONG (Commissioner for Digital Policy, Digital Policy Office) who leads the Digital Policy Office in the formulation of data-driven, user-centric and outcome-based policies and measures that steer government bureaux and departments.


Firstly, he promoted secure digital ecosystem in Hong Kong including Digital Infrastructure, Cybersecurity and Emerging Technologies.


The hall was packed.


And then Ir. Tong Wong introduced government cybersecurity strategy using five pillars including laws, protection, collaboration, community and talent.


Finally, he mentioned the cyber security collaboration in mainland and international. He stated many activities and achievements.


The second keynote speaker was Mr. Jackson CHOW (Cyber Security Director, Wizlynx Cyber Security Limited) and his topic entitled “Exposed by AI: Inside the Next Generation of Red Team Operations”. 


In the beginning, he briefed some emerging cyber threats including emerging technologies, cybercriminals, complex supply chairs,… and uncertain environment. 


Then he demonstrated how AI-enhanced red team operations. He showed the deepfake to break-in the other company meeting. 


After that some application of AI in cyber defenses were discussed.


Finally, he concluded security awareness was vital, audit regularly was needed and security is a collaborative effort.


During break, my bother introduced his boss Mr. June Zhang (Director, HK Enterprise Network Solution Sales Dept., HK Representative Office) and his colleague Mr. Hunter Lau (Solution Architect, Public Seurity Sector of Gov Business Dept, HK Representative Office).


Since I needed to join ANQ Congress online presentation and evening class, I left early and can’t attend Philip’s talk in this afternoon.


I met Ir Patrick Chan who serve in Tencent Cloud as senior industry Solution Expert.


I also met Mr. Ronald Pong (Council member, Smart City Consortium).


In afternoon, Mr. Philip Lai gave a speech entitled “Best Practices for Cybersecurity Enhancement in the Greater Bay Area”.


He discussed the unified cyber security framework between ISO and GB/T standards in Hong Kong.

Reference:

CS Summit - https://www.cssummit.hk/about-cs-summit/

HKSQ - https://hksq.org/

Cybersecurity related past activities:

20230510: HKSQ Webinar on: A Holistic Approach to Privacy Compliance and Recent Update of Information Security Standards - https://qualityalchemist.blogspot.com/2023/05/hksq-webinar-on-holistic-approach-to.html

20220610: HKPC Webinar: Automated Business Continuity & Data Protection in Smart Manufacturing - https://qualityalchemist.blogspot.com/2022/06/hkpc-webinar-automated-business.html

20180831: HKSTP SPARK Seminar on Cyber Security Threat Update - https://qualityalchemist.blogspot.com/2018/08/hkstp-spark-seminar-on-cyber-security.html

20180712: HKAS & HKCTC Seminar on Cybersecurity Testing - https://qualityalchemist.blogspot.com/2018/07/hkas-hkctc-seminar-on-cybersecurity.html

20161026: HKCTC & HKAS Workshop on ISO 27001 ISMS Certification 2016 - https://qualityalchemist.blogspot.com/2016/10/hkctc-hkas-workshop-on-iso-27001-isms.html

20150619: HKCTC & HKAS Workshop on ISO 27001 ISMS Certification - https://qualityalchemist.blogspot.com/2015/06/hkctc-hkas-workshop-on-iso-27001-isms.html

20150424: PMI Seminar on QMS based Information Security Management - https://qualityalchemist.blogspot.com/2015/04/pmi-seminar-on-qms-based-information.html

20130115: HKCTC Seminar on Software Testing Service - https://qualityalchemist.blogspot.com/2013/01/hkctc-seminar-on-software-testing.html

20121129 - Hong Kong IT Security Summit 2012

http://qualityalchemist.blogspot.hk/2012/11/hong-kong-it-security-summit-2012.html

20120620 - Meeting with Prof. Edward Humphreys (Father of ISMS Standard)

http://qualityalchemist.blogspot.hk/2012/06/meeting-with-prof-edward-humphreys.html

20110121 - Seminar on Data Privacy

http://qualityalchemist.blogspot.hk/2011/01/seminar-on-data-privacy.html

20100902 - The 8th Asia Network for Quality (ANQ) Congress

http://qualityalchemist.blogspot.hk/2010/09/8th-asia-network-for-quality-anq.html

20100318: HKSQA Conference 2010 – Software Assessment and Certification - https://qualityalchemist.blogspot.com/2010/03/hksqa-conference-2010-software.html

20090916 - ANQ 2009 Opening & Technical Seminar I

http://qualityalchemist.blogspot.hk/2009/09/anq-2009-opening-technical-seminar-i.html

20090827 - Challenges on Information Security

http://qualityalchemist.blogspot.hk/2009/08/challenges-of-information-security.html

20080802 - Seminar on ISO 9001:2000 UPGRADE to 2008 Version & Secure your information with ISO 27001

http://qualityalchemist.blogspot.hk/2008/08/seminar-on-iso-90012000-upgrade-to-2008.html


2016年10月26日星期三

HKCTC & HKAS Workshop on ISO 27001 ISMS Certification 2016

The Hong Kong Council for Testing and Certification (HKCTC), Hong Kong Accreditation Service (HKAS) and The Hong Kong General Chamber of Small and Medium Business co-organized a Workshop entitled “Workshop on ISO/IEC 27001 Information Security Management System Certification 2016” on 26 Oct 2016.  Certification of ISMS to ISO/IEC 27001 allows an organization to demonstrate that its information asset is adequately protected against information security risk. The workshop aimed to give an overview of ISO/IEC 27001 and discussed how to get prepared for the certification process.  Hong Kong Society for Quality (HKSQ) and Hong Kong Science and Technology Parks Corporation (HKSTP) are supporting organization.  Ms. Angela Wong (Vice-chairman, HKSQ) and I attended the workshop and took a photo for memory.


2015年6月30日星期二

ASTRI visit to HKSTP Technology Support Centre for ISO 27001 experience sharing

I was honor to share our experience on ISO 27001 implemented in Technology Support Centre in HKSTP in which was the first laboratory certified ISO 27001 in Hong Kong.  ASTRI team visited us on 30 Jun 2015 morning.  The following photo is our ISO 27001 certificate with our service scopes.



Visitor of ASTRI Team as follows:
-          Chris Chen (IT Director)
-          Daeman Chan (IT Manager)
-          Jim Hui (Quality Manager)
-          Calvin Shum (Quality Engineer)
-          Winston Oey (Quality Engineer)
-          Astley Wan (Senior Manager, Facility)

The schedule showed below:
(10:30am – 11:00am)
i)                    Briefing the background and implementation issue.
(11:00am – 12:00pm)
ii)                  Visit to WCTL & RL
iii)                Visit to ICFAL & MAL
iv)                Visit to BSC
v)                  Visit to PDTC

Hopefully our experience could assist ASTRI certified ISO 27001 in near future.

Reference:
Related activities:
20150619: HKCTC & HKAS Workshop on ISO 27001 ISMS Certification - https://qualityalchemist.blogspot.com/2015/06/hkctc-hkas-workshop-on-iso-27001-isms.html
20150424: PMI Seminar on QMS based Information Security Management - https://qualityalchemist.blogspot.com/2015/04/pmi-seminar-on-qms-based-information.html
20080802: Seminar on ISO 9001:2000 UPGRADE to 2008 Version & Secure your information with ISO 27001 - https://qualityalchemist.blogspot.com/2008/08/seminar-on-iso-90012000-upgrade-to-2008.html

2015年6月19日星期五

HKCTC & HKAS Workshop on ISO 27001 ISMS Certification

The Hong Kong Council for Testing and Certification (HKCTC), Hong Kong Accreditation Service (HKAS) and Working Group on Cloud Security and Privacy co-organized a Workshop entitled “Workshop on ISO/IEC 27001 Information Security Management System Certification” on 19 Jun 2015. Given the increasing concern over information security in society, more organizations are aware of the advantages of being certified ISO/IEC 27001, which is one of the most well-recognized ISMS standards globally. The workshop aimed to give an overview of ISO/IEC 27001 and discussed how to get prepared for the certification process.

Before the workshop, we took a photo with Mr. Kesson Lee (Secretary-General, HKCTC) and guest speakers. (Left: I, Mr. Ronald Pong, Mr. Kesson Lee (HKCTC), Mr. Ronald Tse, Dr. Kwok Moon-keung (HKAS))


In the beginning, Mr. Kesson Lee (Secretary-General, HKCTC) give an opening remarks and he said ICT was one of focus areas in Testing & Certification Industry.


And then Mr. Vincent Chan (Convenor of the Working Group on Cloud Security and Privacy under Office of the Government Chief Information Officer) gave a welcoming remark. He said public concerned the cloud computing security and introduced InfoCloud website which was established as a one-stop portal for the general public and enterprises (especially the small and medium-sized enterprises) to effectively access information and resources on cloud computing technologies.


All guest speakers took a group photo.


The first speaker was Mr. Ronald Pong (CEO, Nexusguard Consulting Limited) and his topic entitled “Practical Implementation of ISO/IEC 27001 in Your Environment”. Mr. Pong briefed the agenda of his talk included ISO 27001, Different various documents in ISO 27001:2014 series, Vulnerability and Threat, as well as, ISO 27005:2011 risk assessment requirement.


Firstly, Mr. Pong briefed different standards under ISO 27001:2014 series and classified those standards to be “Must”, “Major”, “Reference” and “Supportive”. He explained to us the different between Vulnerability and Thread. Vulnerability was technical problem which could be fixed by updating patch and installation the advance equipment. However, Thread was come from management and human error such as configuration problem and bad practices.


Then he introduced ISO 27005:2011 risk management and its scope included “Constraints related to Methods and Know-How”, “Time Constraints”, “Organization Constraints”, “Environmental Constraints” and “Financial Constraints”. In Organization Constraints, it involved “Development Management”, “HR Management”, “Operation”, “Administrative Management” and “Maintenance”. The standard risk matrix was also mentioned.


Finally, Mr. Ronald Pong briefed ISO 27003:2010 for ISMS implementation guidance and the first thing to do was your information inventory classification. ISO 27006 & ISO 27007 was related to certification body such as auditor manday criteria for Large/Small and Simple/Complex companies.

During the break, I took a photo with Dr. Kwok Moon-keung (Senior Accreditation Officer, HKAS) who was one of assessor to audit our laboratories before.


I was honor to represent HKSTP to be the second speaker and my presentation named “QMS based Information Security Management System – Case Study”. Our Technology Support Centre (TSC) achieved ISO 27001 since 2008 and I reviewed many security incident happened in Hong Kong at that time. We had upgraded the standard to ISO 27001:2013 for whole TSC at the end of 2014.


Then I introduced the development of InfoSec FMEA Circle as our key risk assessment tools (where FMEA stands for Failure Mode and Effect Analysis). Then its implementation philosophy was mentioned. It was based on ISO 27001 Control Objectives & Controls as fundamental level and then evaluation risk level on each operation information flow accordingly.


After that 24-steps QISM Implementation Roadmap was introduced and its development was based on TQM Roadmap. We focused on 7 phase including “Awareness”, “Preparation”, “Plan”, “Do”, “Check”, “Act” and “Validation”. I also discussed how to establish our risk assessment criteria. The details was published in the Journal (See reference).


At the end, I used the term “SECURE” to conclude our ISMS implementation and it indicated “Standardization”, “Effectiveness”, “Clearance”, “Unique Identification”, “Recovery” and “Efficiency”.

The third speaker was Mr. Ronald Tse (Founder of Ribose) and his topic was “The SME pocket guide to achieving ISO/IEC 27001 certification”. Mr. Tse introduced his company which provided a secure cloud collaboration service.


Then Mr. Ronald Tse briefed his ISO 27001 journey and shared some tips to achieve it. He briefed ISO 27001 was suitable for SME. He added “Big names say: We are ACME therefore your data is secure. SMEs can say: We are independently certified for ISO/IEC 27001!” Then he showed different security management maturity level which ISO 27001 could help to improve it.


Mr. Tse said leadership commitment was crucial to a successful ISMS implementation. He shared to list each specific duty unit and subunit to perform risk management and set appropriate IS objectives. Finally, Mr. Tse told us the fastest way to implement ISMS successfully was to lead by yourself but not shortcut!


Dr. Kwok Moon-keung (Senior Accreditation Officer, HKAS) was the last speaker and his topic named “Hong Kong Accreditation Service (HKAS) – How its Services Help You”. Dr. Kwok introduced that Accreditation which was issuance of conformance statement by a third party (i.e. accreditation body) to a conformity assessment body (i.e. laboratory, inspection body or certification body, validation and verification body) and conveying formal demonstration of its competence to carry our specific conformity assessment tasks. (ISO/IEC 17024)


Accreditation helps managing the risk. The relationship among accreditation body, certification body/laboratory and users was showed in the following diagram. Dr. Kwok described how to monitor accredited organization including “Reassessment”, “Surveillance visit”, “Monitoring organization change”, “Complaints” and “Proficiency Testing / Inter-laboratory Comparison Study”, etc.


Finally, Dr. Kwok introduced HKCAS services which extended to ISO 27001.


Reference:
HKCTC - http://www.hkctc.gov.hk/en/home.html
HKCTC Seminar presentation file - http://www.hkctc.gov.hk/en/work_seminars.html#b44
HKAS - http://www.itc.gov.hk/en/quality/hkas/about.htm
OGCIO - Working Group on Cloud Security and Privacy (WGCSP) - http://www.ogcio.gov.hk/en/about_us/committees/egccss/previous_term/wgcsp_tor_membership_2013.htm 
InfoCloud website - http://www.infocloud.gov.hk/home/20
20150424: PMI Seminar on QMS based Information Security Management - http://qualityalchemist.blogspot.hk/2015/04/pmi-seminar-on-qms-based-information.html
Lai, Lotto K.H. and K.S. Chin (2014) “Development of a Failure Mode and Effects Analysis Based Risk Assessment Tool for Information Security”, Industrial Engineering & Management Systems, Vol 13, No. 1, pp.88-101.
Lai, Lotto K.H., Chin, K.S. & Tsang, A.H.C. (2010) “Risk Management of Information Security – Information Security FMEA Circle” The eighth ANQ Congress, paper HK01. (Reprinted in SQI Yearbook 2011, pp.66-72)
Lai, Lotto K.H., Chin, K.S. & Tsang, A.H.C. (2009) “Integration of Quality Management System and Information Security Management System – HKSTP implementation case” Proceedings CD-ROM of The seventh ANQ Congress, paper HK02.

2015年4月24日星期五

PMI Seminar on QMS based Information Security Management

I was honor to be invited as speaker for the PMI seminar entitled "Case Study on the Project Implementation of Quality based Information Security Management" was organized by Project Management Institute (PMI) Hong Kong Chapter on 24th Apr 2015. The aim of this seminar to share the system approach through integrated implementation of an Information Security Management System (ISMS – ISO 27001) and Quality Management System (QMS – ISO 9001), as well as, case study in Technology Support Centre (TSC) of Hong Kong Science and Technology Parks Corporation (HKSTP).

In the beginning, I (Former Chairman, HKSQ; Manager, Quality System, TSC-HKSTP) introduced some background of ISO 27001 and ISO 9001. Our ISO 27001 has certified since 2008. So I briefed many security incidents which had happened in 2008 initially.


Then I classified different Control Objectives and Controls into five groups and they were “Policy”, “Process & Procedure”, “Organization Structure”, “Hardware” and “Software”.


The comparison of company registration on ISO 9001 and ISO 27001, it was found that number of ISO 9001 certified companies were much higher than number of ISO 27001 certified companies. It should be a barrier for company to achieve ISO 27001. Therefore, my study was to develop a model so as to fill the gap.


ISO 9001 and ISO 27001 principles and standard comparison was discussed. In next stage, I explained how to extract the core elements of both standards and developed “QMS based Information Security Management (QISM) Model”. However, the core element of this model was Risk Assessment. “Information Security FMEA Cycle” was introduced and 24-steps QISM Implementation Roadmap was mentioned.


At the end, I used the term “SECURE” to be my concluded. Its meaning showed below:
S – Standardization
E – Effectiveness
C – Clearance
U – Unique Identification
R – Recovery
E – Efficiency


Q&A Session


Mr. Anthony Tsui (VP-Programs, PMI-HK) presented a certificate to me.


Reference:
HKSQ - www.hksq.org
HKSTP - http://www.hkstp.org/
PMI-HK - http://www.pmi.org.hk/

Other Related Seminars & Conferences:
20141229 - My ISO Journey of 10 years in Science Park
http://qualityalchemist.blogspot.hk/2014/12/my-iso-journey-of-10-years-in-science.html
20121129 - Hong Kong IT Security Summit 2012
http://qualityalchemist.blogspot.hk/2012/11/hong-kong-it-security-summit-2012.html
20120620 - Meeting with Prof. Edward Humphreys (Father of ISMS Standard)
http://qualityalchemist.blogspot.hk/2012/06/meeting-with-prof-edward-humphreys.html
20110121 - Seminar on Data Privacy
http://qualityalchemist.blogspot.hk/2011/01/seminar-on-data-privacy.html
20100902 - The 8th Asia Network for Quality (ANQ) Congress
http://qualityalchemist.blogspot.hk/2010/09/8th-asia-network-for-quality-anq.html
20090916 - ANQ 2009 Opening & Technical Seminar I
http://qualityalchemist.blogspot.hk/2009/09/anq-2009-opening-technical-seminar-i.html
20090827 - Challenges on Information Security
http://qualityalchemist.blogspot.hk/2009/08/challenges-of-information-security.html
20080802 - Seminar on ISO 9001:2000 UPGRADE to 2008 Version & Secure your information with ISO 27001
http://qualityalchemist.blogspot.hk/2008/08/seminar-on-iso-90012000-upgrade-to-2008.html


LinkWithin

Related Posts with Thumbnails