We are implementing ISO 27001 in our department which is apart from HR, Procurement, and EVEN IT department, How can we apply so many IT related things in our department? Plus, we are working with contractors and those contractors are using subcontractors for our work, how can we apply risk assessment and treatment plan on them?
ISO 27001 and ISO 27002
ISMS for a cloud provider
Process in ISO 27001?
Roles for ISO 27k, how many layers are needed?
I have a question about the ISMS roles in a small organisation. We’re a company of about 20 employees, so naturally there are not many management layers. Basically we have COO and CEO above the ISMS team, and this makes assigning the roles a bit challenging. Do you have a recommendation what roles are needed for a small organisation for ISO 27k? We currently do not have formal roles of e.g. quality manager, or head of information security, but we can