Control A.5.1.1 Policies for information security - when to select it?
During the ISO27001:2013 implementation process it is of course mandataory at the first stage to define the ISMS scope, to obtain the support of the top management and to formalize a high level Information Security Policy. But during the SOA step is it necessary to select the ISO 27002 control related to Information Security Policy in order to write down a detailed Infomation Security Policy ?
Providing ISO 27001 audits for clients
I am looking to provide iso270001 audits for my clients. If I take the course and pass the test will that allow me to perform audits for my customers and certify their businesses for iso270001?
BCP for the ISMS?
¿Qué procesos críticos seleccionar para la implementación de ISO 27001?
Mandatory documents and Risk Treatment Plan table
What standard for data center?
Internal and external issues, requirements of interested parties
We are BPO organization and external auditor marked us following NC "Internal and External Issues are addressed in Risk Assessments which can be more clearly established. Also the requirements of Interested parties can be further elaborated." How can we overcome on above mentioned NC?
Basic requirements and documents of ISO 22301
Appendix 4: Examples of disruptive incidents scenarios
Difference between information asset and IT asset?