Guest
How to set up a good RTP
How long must a sgsi (ISMS) be operating to pass the certification process
We have been struggling to get our measures and metrics right. Is there any best practice or education around measures and metrics?
We are ISO certified organization and due to COVID 19, we are not able to comply controls i.e. backup tapes movement from one location to off-site location
How do we address this? Is there any advisory published by ISO / any template /format where we can mention this and take approval from management & it will be helpful during the audit as well.
How an auditor can verify that agreed corrective actions have been effectively implemented?
Is it typical in smaller companies (50-100 employees) that for the internal audit an external auditor is being hired? Or should you be thinking of somebody internally in the first place anyhow?
1. I'm reading the Business continuity Policy according to ISO 22301; I Don't understand why it is written, "Because in many cases the executives have no idea how business continuity can help their organization, which means they won’t be particularly interested in supporting the business continuity effort in their company."
How it can be possible?
2. If they are not involved that plant will be closed?
Hello, I am having a hard time understanding the difference between BCP and DR. I know for our ISO cert we have to include a.17.4.6 right? That is the Disaster Recovery Plan, but our certifier is saying we do not have to complete the Business Continuity Plan, which is the rest of a.17, why is that?
Many thanks for offering the Lead Auditor ISO27001, I was wondering if one has to start an audit, is there any process chart that can be used as guide ( like a flow chart )
Define Scope --> Review ISP and related documents --> Perfrom SOA --> etc
Something similar to Diagram of ISO27001 Implementation process but for conducting an audit
Cheers
Alex