ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • ISO 27001 certification benefits

    As a managed service provider with ISO27001 accreditation, how does this help a customer who has a requirement that their provider is accredited with ISO27001?

  • 7 Controls in the A.6

    Just to ask what are the 7 controls in the A.6

  • Measures Appendix A

    1 - we are in possession of your toolkit for ISO 27001 and are in point 6 (declaration of applicability). The 114 specified measures are to be checked for applicability. For us, however, the question arises as to whether all measures really have to be applied, since theoretically quite a few of them could be used or whether only suitable measures have to be defined for the risks that we have assessed with risk levels 3 and 4 (unacceptable risks).

    2 - In addition, we would like to know whether there are any legal regulations in Germany to which we must pay special attention in the course of the introduction of Iso 27001.

  • Complying with ISO 27001 and EU GDPR

    Can an IT company with 1 employee and working with freelancers/consultants be compliant with iso27001 and gdpr?(Gdpr requires a data privacy officer)

  • ISO 27001: DevOps toolchains

    How can ISO 27001 be granted if all changes are only visible in DevOps toolchains? Changes are no longer approved and implemented, only playbooks in Jenkins, Ansible, Docker or OpenShift are started. Can these tools be viewed as a certified management system?

  • BCP/DRP

    Just considering with the threat of hackers and cybersecurity being rampant now, how to approach the BCP/DRP in my planning?

  • FCS security governance critical success factor

    I want to write a risk assessment table , do we include the asset category, CWE, vulnerability, likelihood , impact and risk in the table column or not

  • ISO 27001 Certification

    I have just obtained my CISSP, working on CISM what would you recommend that I do to start progress towards becoming an ISO 27001 Standards consultant, what would my next best certification be? I am looking at getting my PMP after completing the CISM.

  • Submitting records for approval

    Just getting started writing policy for ISO 27001. I have completed the Context, Requirements and Scope document. Is it better to move on and create/finish more documents and approve/distribute all at once with management or start document approvals now risking updates/adjustments as more progress is made?