ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Scope definition

    In your blog describing problems with defining the scope in ISO 27001, there is a discussion about problems related to narrowing the scope to part of the organization, as opposed to the whole organization. It is not clear to me whether there would be problems in the situation where the whole organization is included, but only a specific type of information (e.g. only health information) is included in the scope. Do you predict problems with narrowing the scope based on the type of information?
  • Example of assets

    I need assistance on likely information security assets in a manufacture company.
  • Segregation of responsibilities

    Could you please explain this: to separate the operational responsibility for networks from the responsibility for sensitive applications and other systems
  • Risk treatment options

    What about reducing and sharing the risks?¸
  • Risk assessment and PIA for EU GDPR

    What about PIA for the EUGDPR - will the risk assessments for ISO be useful for this?
  • Measuring control effectiveness

    Lets say that for example my company does not have any IDS system, how could i measure for example the probability of breach, and after implementing for example 2 factor authentication how would i measure the effectivness?
  • References on Procedure for Document Control in Toolkit

    In the document control procedure section 2, why are there references to 22301 and BS 25999 which are business continuity related. surely they do not apply to iso 2700? So what reference documents should be referred to then please.
  • Supply chain risks

    What about supply chain risks? What parameters are used for vulnerability measuring ?
  • Risk management in e-learning course

    I need a clarification. Talking about the Risk Assessment and_Risk Treatment Methodology it is enough to attend the specific chapter in your e-learning course, in order to manage the Risk Phase (small organization, starting from the scratch).
  • Risk evaluation

    1 - Can you explain how assets are evaluated in terms of CIA. and how it would contribute to risk prioritization?