I have an enquiry about becoming an ISO 27001 auditor. Once I completed the Auditor training course, can I start support doing audits and what rate would I typically expect to work at as a consultant?
Clauses 4.1 and 4.4
Please let me where I could find the templates related to clause 4.1 and 4.4
Structure of the Risk Treatment Plan
Hi friends,
I have a doubt about the Risk Treatment Plan, How to structure it? For example, can I to organize the RTP according to risks? controls? assets? o according what?
Which columns should have it? and which is the best way to do this document according the ISO?
Thank you.
Quick Risk assessment
I have a document with many questions to check against my software, based in the controls of ISO. The System shall have a logoff button. So, I am compliant or not. If I am not compliant, so I need to do the risk for this item? Using the matrix to calculate. After do it for all items I did the risk assessment? Is it the correct why to do the risk assessment?
Business Continuity
I have a question, I´m going to work in process for business continuity (A.17.1.x), but I don´t have a clear idea for this process. Do you have any document or some guide that I can use for this part or just for the item A.17.1.2.
Disaster
a.- Do you have available articles, where you give your advice in how to define a disaster in a DR plan?
Asset management
Concerning my query on Asset Management
ISO 27001 on a personal level
I was interested to learn about iso 27001 on a personal level, but it is a bit much for a small organization with no formal security, no compliance requirements, and no desire to add security.
Clause 7.2
I noticed in the article indicated that the clause 7.2 is included in internal issues. I must prove that people involved in the implementation of the ISMS has competence to perform these tasks, or should I just have evidence that gave training to all company employees to become aware?
Your organization and your customer
Please, I would like to ask about ISO 27001. I have on doubt. For example, I selling a SYSTEM. So, my customer has whole infrastructure to support the SYSTEM that he bought from me. Servers, Storage, Network. I just create and install the SYSTEM on the customer environment. All management is customers own.