ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • 27001 certification process

    In our organization, we have a bit of a misunderstanding on who “owns the 27001 certification process.” Security feels as though it’s theirs, and the Quality group (since we’re ISO 9001 certified too) feels it’s theirs. Probably worth mentioning that our quality people hold the relationship with the external audit company, so that’s something of a contributing factor as well.
  • Gap Analysis for ISO 22301

    I am wandering if you have something like a Gap Analysis for ISO 22301.
  • Assigning value to assets

    1 - How to assign value to asset quantitatively corresponding to Confidentiality, Integrity and Availability.?
  • How often should the controls be audited

    I have a few questions following watching the video.
  • EU ePrivacy review

    I want to know what changes are proposed in Directive 2002/58/EC to bring it inline with EUGDPR.
  • Risk management process flow chart

    May you please help me with a sample of a Risk Management process flow chart. We are gunning for ISO certification so I need a template to use and later on I will design a manual as well. I just need a skeleton copy.
  • BCP and ISMS

    As per ISO 27001:2005- BCP to be implemented in the whole scope of ISMS.
  • BIA scope

    I am facing an issue where the operation department within the organization has only provided me with the main services provided and they cannot decide what the support services are. For example, the HR department handles salaries and Its considered a support activity which needs to be part of the BIA. However, the HR department also has activities which are unrelated to the main activities. So how can I decide on what activities are considered related and unrelated, is there an example you can provide me that will detail what to add and what to avoid.
  • IT assets

    I am facing few issues regarding drafting asset inventory, which are as follows-
  • Difference between internal and lead auditor courses

    Lead Auditor and Internal Auditor courses actually refer to 2 different things?