Guest
What is the version of ISO 27001 that your documentation is compliant with?
I just viewed the ISO/IEC 27701 Privacy information management standard (First edition 2019-08) and I have learned that there are more than some minor modifications. In the Advisera documentation kit ISO27001/GDPR, I do not see (yet) anything about this.
Do you have an idea how to best deal with this, I do not find anything on the Advisera website about it (unless I have overlooked something)? Will there be a publication and/or webinar/additional documentation available (can be payable) in the near future from Advisera part?"
How to prepare an action plan after external auditor has given minor NC?
I have the following question regarding a decision which impacts the ISO27001:
The owner/management (small company) has a company e-mail addresses. The owner does not like working with the company e-mail solution, so he wants to automatically forward the incoming e-mails from his company inbox to his private email account (with Gmail). Additionally, he wants to send E-mails from his private email account where the sender will be shown as his company email. The use of private email addresses is generally prohibited (currently implementing policy for employees etc.). Is it possible to create an exclusion in the policies for the owner/CEO and what other implications does this e-mail forwarding/relay have with regard to the ISO27001 certification? The whole company is in the ISMS scope, but not the mentioned private email account.
Hi, I am an IT Audit Manager at XXXX and XXXX maintains 3 different ISO 27001 certifications on different continents. There are only 2 of us working on ISO internal auditing and we are finding that testing all of the controls for 3 programs is no longer feasible, even if we divide them up over 3 years. Is it actually required that every control is tested by internal audit every 3 years? Or is there an easier way? How do other companies do this? Any help you can give would be appreciated.
Can you pls share the link of third party risk assessment questionnaire?
Can someone be lead Auditor and implementer consultant at the same time?
When certifying ISMS according to ISO 27001, what additional documentation do I need for ISO 9001 certification of QMS?