I have a question, the CISO shall be mandatory under the CEO of the company in the structure of the company or is fine to be also under the COO ? According to the ISO27001 where is stated to be placed the CISO? We are under ISO27001 implementation and we have this debate and I want to understand if we are ok with that . From my perspective if the CISO has the right budget and profile in the organisation to make the things according to the standards can be as well under the COO.
Integrated inventory of assets
I have what probably is a question that would be hard to answer.
Risk management process
I just need a few more information to understand the context between risk assessment, risk treatment and annex a. (I already watches all of Dejan’s Video tutorials and read his advice on your page).
ISO 27001 and NESA
How to link ISO 27001 With other standard like NESA ?
Specifications for server room
I'm looking for a section that gives the physical security and building standards for a server room. In other words the building standard requirements.
Controls documentation
In regards to the documentation of the controls we have decided to implement for 27001 how do we document how we actually do things? Or do we even need to?
Information classification template
I am working on document A.8.3. In this document the following is stated:
Filling a SoA template
Hello rhandleal,
ISO 19001:2018
My main concern is that your book is the First Edition, 2017, and is obviously based on ISO 19011:2011. As you would know, ISO 19011:2018 has just been published, so I am wondering to what extend my book is now obsolete and I have only had it for approximately two months. So knowing this, it is difficult for me to say if it will be of any use to me, and has been a waste of money. I don’t have the time to compare it with the new edition (2018) of ISO 19011.
ISO 27001 & Regulatory laws
Hi, Just a quick one. Does being ISO 27001 compliant automatically means being regulatory & local laws compliant ?
Can a company be ISO 27001 compliant without being compliant with local & regulatory laws ?