ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Operation and practices documented

    If the operation and practices are in place but it is not documented, then how to rate that risk, High medium or low
  • Implementacion ISO 27001

     Me ha sido de gran apoyo toda la documentación y correos enviados; te platico que nosotros estamos en México y deseamos certificarnos en ISO 27001-2013, necesito saber en qué me pueden apoyar (Implementación, cursos, norma, certificación, etc)  y cuál es el costo.
  • Does all the Policies and procedured need to be in Word/PDf format?

    Does all the Policies and procedured need to be in Word/PDf format?. I am right now preparing a communication policy. As per ISO 27001, commuication policy should define who, wat, when and how to comunicate. Can i maintain all these in the excel file, just like shown below. Will that be accepted as a policy? or is there a better way....   What to Communicate When To Whom How Who shall Communicate Records Owner Internal Audit Plan As per the periodicity defined in IQA PL's eMail SQA Internal Audit Records SQA
  • Employee equipment in the ISMS scope?

    This is an awesome template, but I do have one question.  Why’d you leave out data and employee equipment?  I consider employee laptops in scope, but it doesn’t seem to fit into the categories in the template unless I put it under Processes and Services.
  • Responsabilidad de la dirección y gestion de los recursos

    Qué me puede decir acerca de la "responsabilidad de la dirección" y la "gestión de los recursos" de la norma iso 27001?
  • Some particular controls partially implemented

    I declare the status "Partially implemented" for some particular controls in SOA, for which I must write a Policy document. I put this task in Risk Treatment Plan, e.g.: write a Policy document. Is it necessary to review the SOA after implementation (after writing that Policy document) and update the status of controls to "Fully implemented"?
  • Type of assets

    Can workstations be an Asset class?
  • Maintenance of the ISMS

     Thank you for your e-mail and available documentation, it has really helped me comprehend the ISO certification procedure.
  • Generic SOA

     Can you help to list out generic SOA for power generation system.They are isolated network and no wireless.kindly explain why the controls are applicable and not applicable.
  • Adaptation to ISO 27001:2013

     Is the expiry date for my certificate the one stated on the certificate, or is it 1st Oct 2015? The expiry date stated on my certificate is NOV 2015.