Guest
problem statement: an external auditor company did not include WFH or teleworking in their audit plan, but the company had already implemented an "ad hoc" WFH during this pandemic without consultation with employees and without government regulatory approval.
1 - can external auditor still considered this compliant and an ISO/IEC 27001 certification be awarded to the company?
2 - is there such thing as partial certification?
I need details on documents assets. Do we consider the employee information spreadsheet also an information asset? Or is just the agreements, contracts etc, which are considered as assets? Please clarify.
When we get ourselves checked for surveillance of ISO 27001 standard, we do receive non-conformities. We perform a root cause analysis and corrective action plan for the non-conformities and work to conform them. I would like to know if you have a template to perform the root cause analysis like the fishbone method etc.
Is ISO 27001 relevant for clinical data management?
I'm in the process of an audit for license and patch management for an internal audit...Which documentation is needed for such audit process?
Please I need some professional advice
A holding/group/mother company with other legal subsidiary companies want to implement ISMS for the group with the scope including the subsidiary companies.
The Group company and the subsidiary companies are all located at the same place
The same staff works for both the Group company and subsidiary company
They both share the same assets.
But the subsidiary companies offer different products and services
What do you suggest should be the best way to implement the ISMS towards achieving Certification?