ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Toolkit documentation

    I have purchased the 27001 / 22301 premium collection. When I look at the Annex A section A.6 Organization of information security I do not have any document templates for A6.1.1, A6.1.2, A6.1.3, A6.1.4 or A6.1.5? Where are these document templates?
  • Security requirements checking and testing

    Under secure development - checking and testing the implementation of security requirement can you please explain:
  • Business Continuity Strategies

    I work on the BC strategy document. Please explain where should I define detailed recovery strategy for individual applications. The various critical activities defined by BIA analysis use xxxxxxx as an application that access the servers and it is absolutely critical, but I was wondering where and how to define recovery for the xxxxxxx - whether as a separate Activity recovery plan (which I would perhaps call application recovery plan ) or otherwise?
  • ISO management systems compatibility

    I am working with development of an Integrated Management System for Quality with the ISO 9001,2015 as the base standard and ISO 22002 and ISO/TS 22002-1 Pre-Requisite standard for FOOD SAFETY, into Clause 6 of ISO 9001.2015 ( Risk Based Thinking).
  • Backup control

    Como aplicar la norma de seguridad de la información , en cuanto al tema de respaldos (How to apply the information security standard, regarding the subject of backups)
  • BCP project budget

    We have a client who requires a BCP end to end plan for a Health care industry and the project is in US. We are from India and not sure about calculating the Budget for a project duration of 4-5 months. The client has requested for a Fixed time pay. Please help us how to calculate the Budget.
  • Benefits from ISO 27018

    Looking for advance to describe the demarcation points between 27001 & 27018
  • Controls elaboration

    Gostaria de saber como faria para dar uma nova roupagem nos controles da norma, isto é, como eu faria para falar de alguns controles da norma 27001 com as minhas próprias palavras, em vez de copiar e colar informações sobre os controles da norma.
  • Records maintenance

    Regarding software Requirements and Software design, Is there any fancy way of writing and maintaining records? As a developer we don't like to read a document with 100s of lines.
  • BCP and DRP

    Currently we have DR Site, we do have a Disaster Recovery plan - Currently we don't have any BCP - However what I understand is Disaster Recovery plan is a part of BCP. currently as per the advise from the security company to write a procedure in BCP. I wanted to understand that how to implement BCP and the core difference between them and how to accommodate it within our organization.? BCP means as Global which needs to include not only IT department but also to involve HR, Finance and management?