There are no topics yet.
1. Just a quick question. After you go through all the steps in the ISO27001, and after you get the recertification, do you need to redo a risk assessment every year? Or do you just follow-up on the risks?
2. And risk-wise, do you do a threat modeling/profiling to better capture risks or what would you recommend?
3. And finally, what would you recommend to do yearly (and plan yearly) so that the certificate is kept in good health? Thank you very much in advance, any help is indeed greatly appreciated.
1. As part of ISMS implementation, do we have to make all the Advisera Templates be read and understood by all the colleagues in the Organization after filling up the Templates or just only Information Security Policy Document?
2. In every doc, it is mentioned as “Users of this document are [job title].” So here should we mention the concerned approver or the Person e.g. (CISO or all the User in the Department).
How would you describe the differences and overlaps between the jobs of a Compliance officer, DPO, CISO?
When identifying assets, can I lump them together or is it each one individually that needs a Risk Assessment completed?
Eg. 10 Servers are identified as critical assets. Can I do a Risk Assessment on Servers or do I need to list CLIENTSVR01 in the risk register.
I'm actually looking for an IOS standard for physical security rather than ICT security. If you could advise me if an IOS standard exists for physical security I'd be very keen to look at how this might be implemented.
From whom do you have the ISO 27001 implementation in Germany certified in Germany? From the TÜV?
Since we have to list all the List of Legal, Regulatory, Contractual and Other Requirements in the attached form, do we have to list all the Regulations and the laws listed under the Particular Country(see Link Below). For eg, In the case of Germany, while listing the requirements do we have to list all the requirements listed under Germany in the attached Document?
I have been appointed to help the company get ISO and EIDAS certification. I have to start from scratch as I know NOTHING about security or compliancy… So this newborn Compliancy Officer hopes she can turn to you to help her – I am very nervous about the whole thing. I purchased the toolkit and I am currently working on WIP00_Procedure_for_Document_and_Record_Control_Integrated_EN
The questions I have:
1. “Mail significant for the planning and operation of the ISMS/compliance with GDPR” should be recorded. This can be an exell on our Sharepoint or an actual paper/pen notebook at the office I assume. What would, in reality, be such mail? I can think e.g. someone who would send a letter executing his “right to be forgotten”.
I will have to explain to the others in the company which mail they will have to register and what will not be considered as “mail significant for the planning and operation of the ISMS/compliance with GDPR”, but I don’t really know the answer to that myself yet…
2. I want to make a list per function/role in the company of all the responsibilities and tasks as described trough the policies and procedures. Is there already a template for this? I don’t find it in the kit.
3. Also, is there a list of all ISMS related type of roles? As CISO, Senior Management, Compliancy Officer, DPO…?
I'm on a tight deadline to write a Disaster Recovery policy that is compliant with ISO/IEC, HIPAA, NIST, and SOC 2, maybe some others.
1. Do you have any suggestions for me?
2. What other ISO standard is associated with the ISO/IEC 27001 and 27002?
Can you share me the of what is the difference between ISO27001 AND NESA?