We produce a cloud-based web application that is hosted on XXXX and uses other outsourced infrastructure providers (like XXXX). The only physical equipment that the company owns and that is onsite in our offices is employee laptops. Considering this situation, are the ISO 27001 controls in Annex A sections A.11 (Physical and environmental security) applicable to us, since we don't have any servers or other major equipment onsite?
Certifications for ISO 27001 experts
Is there a specific global certification for experts? Allows expert people to work to help organizations obtain ISO 27001 certification.
BCP and Measurement report templates
I have two question. I am looking into drafting this two documents:
Information classification
I have a difficulty right now to understand how to classify Information with regard to documents.
Control justification on SoA
I have additional question. Is “Justification for selection/non-selection” column mandatory or voluntary to use?
Legal requirements
For the “control objective A.18 – Compliance with legal and contractual requirements” – does this need to include other legal requirements or is it just those relating to information security. For example should the legal register hold reference to the Companies Act and other Financial Regulations – as these are not specifically related to information security.
Alcance ISO 27001
"Mi pregunta esta orientada a la iso 27001. Para poder certificarse debe participar toda la empresa o solo el area it?"
Prospective questionnaires
I sometimes receive questionnaires from prospective customers to assess our level of security.
Non permitted technology strategy
One fast question as I have to have a draft for a customer by Friday on the following and I’m curious where I should put this within the existing toolkits:
ISMS scope on cloud environments
I am working in a company which delivers an iPaas located on Azure (Azure is already ISO 27001 certified). What is the difference between the ISMS scope for an iPaas and a SaaS?