ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Sharing a server cabinet - is this compliant with ISO 27001?

    One of the business units which is not in our scope for accreditation is partially owned by ***. I know the particular business unit in question does not have access to our network at all but I am awaiting confirmation as to whether we share a server cabinet with them. I don’t think this is the case but if we do, can you please advise if this may hinder our compliance with any of the standards?
  • ISO 27001 Risk Management

    I’d like to ask a question about risk management process in ISO 27001. During risk management process; we determine risks, analyze their impact and likelihood, choose a risk treatment option and at last choose a control against that risk.
  • Difference Between ISO 22301 & ISO 22316

    Is there any major difference on ISO 22301 & ISO 22316. I understand ISO 22301 is certification standards and ISO 22316 is Guidelines for planning Organization resiliency.
  • Recertification or surveillance audit?

    Our organization got certified as ISO 27001:2005 in April'2014. But now
  • Annex SL Implementation for ISO 27001:2013

    Need your guidance around Annex SL in conjunction with ISO 27001. Particularity can you please provide me detail documentation or white paper around "how to implement ISO 27001:2013 using Annex SL. OR. how to leverage Annex SL to implement ISO 27001:2013 frame work.
  • ISO 27001 Exam

    I'd like to ask which documentation should I use in order to study for the ISO 27001 PECB exam.
  • Cyber Security - ISO 27001

    I note that within the new ISO 27002 Code of Practice, there are no controls for cyber security.  With this in mind, would the mitigation of cyber security be addressed with network architecture kept under review and implemented, use of IDS/IPS with their configuration kept up to date for access requirements, firewalls maintained correctly, policies & procedures and maintaining a proactive posture.
  • Regarding ISMS certification and accreditation

    I've completed ISMS LA 2005 certification from BSI in June 2012. It is going to expire in June 2015. As of now, I can do only internal audit within an organization. May I know how can I get accreditation so that I can do external audit.
  • KPI for IT Disaster Recovery

    I was trying to define key performance indicators for our company's IT Disaster Recovery capabilities. Some of them i could find are as follows:
  • Information Risk Management

    How do i help/provide a professional consultancy service to a in a manufacturing industry on information risk management?