ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Audit checklist

    For the audit checklist document, 10.3, we are just doing ISO27001, does the auditor need to complete the whole checklist?  Can pieces be done over time?  Can you just sample the checklist and issue a report to meet the standard?

  • Using ISO 27001 and 27017 to get GDPR compliance

    I wanted to know if it's not possible to use ISO 27001 and possibly 27017 to get to GDPR compliance so it's all embedded in a system as opposed to separate controls to cover a regulation

  • ISO27001 for a Cloud Service Provider

    I am looking to do ISO27001 for one of our businesses which offers Cloud Services only.  I presume ISO27001 should more than cover the services offered for this type of provider.  Would they be similar to a Data Centre Provider?

  • GDPR and ISMS

    I am now doing some exams for GDPR and in this course I've learned that ISMS is one of the strategies you can take. I have been in contact with some implementation stuff in ISMS. I would like to certify in ISO27001 but to cover GDPR which course is right for me?

  • ISO 270001 standard implementation

    If the company has a server room, is it mandatory to have a disaster recovery site to be certified?

  • ISO 27001 stakeholders

    Who are iso 27001 stakeholders? How do we identify them? Are top managers included in the ISMS scope?
  • Business Impact Analysis report

     By the way, does this (ISO 22301 Business Impact Analysis Toolkit) come with an actual sample Business Impact Analysis report? I could find in the toolkit the document named as the client mentioned so I wanted to check if the document is named differently or it's not included in the toolkit.

  • Experience for taking up ISO27001

    hi. is the 4 years experience in IT mandatory prior taking up ISO27001?

  • SoA and selection of controls

    I have a question about SoA and selection of controls:

    If control is selected as applicable in which extent the control is required to implement?

    For example: if  control A.9.4.3 Password management system is selected as applicable is it required to implement to every single system/application in the Company or is it enough to implement it according to assessed need (based on assessed risks and other relevant information concerning the systems/applications)?

  • Question about non-compliance

    What would be the consequence for non-compliance?