Guest
Sorry, i'm reaching you for a Quick answer since i'm not updated with the current classification of findings for ISMS. Still current opportunity for improvement, observation, minor and Major NC?, or just NC & OBSERVATIONS?.
I have Been looking for a response but not sure, several opinions and i'm confident that you could help me.
is it a nonconformity if the polices version numbers not equivalent according to iso 27001?
ello, could you explain why in this article https://advisera.com/27001academy/iso-27001-controls/
you have mentioned only controls from A5? What are the A1 - A4 controls about? I cannot find the information on this.
As a managed service provider with ISO27001 accreditation, how does this help a customer who has a requirement that their provider is accredited with ISO27001?
Just to ask what are the 7 controls in the A.6
1 - we are in possession of your toolkit for ISO 27001 and are in point 6 (declaration of applicability). The 114 specified measures are to be checked for applicability. For us, however, the question arises as to whether all measures really have to be applied, since theoretically quite a few of them could be used or whether only suitable measures have to be defined for the risks that we have assessed with risk levels 3 and 4 (unacceptable risks).
2 - In addition, we would like to know whether there are any legal regulations in Germany to which we must pay special attention in the course of the introduction of Iso 27001.
Can an IT company with 1 employee and working with freelancers/consultants be compliant with iso27001 and gdpr?(Gdpr requires a data privacy officer)
How can ISO 27001 be granted if all changes are only visible in DevOps toolchains? Changes are no longer approved and implemented, only playbooks in Jenkins, Ansible, Docker or OpenShift are started. Can these tools be viewed as a certified management system?
Just considering with the threat of hackers and cybersecurity being rampant now, how to approach the BCP/DRP in my planning?
I want to write a risk assessment table , do we include the asset category, CWE, vulnerability, likelihood , impact and risk in the table column or not