Guest
Hi. Been working as a part time Consultant for *** for close to 6 years now.
However, a friend told me about Lead Auditor late last year and really got me interested.
I do not have experience in Information System Security or a lot of Information security given that *** is a LIMS company.
Please advise how I can change my career to Lead Auditing from Laboratory Information Management Systems configurations.
I wonder whether you could advise me, We are planning to have a ISO27001 assessment but assessment team is planning to audit the Business function assets as well. However as far as I know ISO27001 is dealing with Corporate functions only (workplace, HR, IT, Procurement...). Could you let me know whether my understanding is correct? Is there any article already written on this please?
How would you approach preparing for an audit taking place in 8 weeks, what would you prioritise, how would you ensure non-conformities are minimised
New to the ISO 27001 space, on my first day with my first client, what discussions do I need to engage in, what do I need to do, what to ask, who to engage etc. to commence 1) an ISO 27001 audit 2) ISO27001 Implementation?
I am going through the documentation and have a question regarding the Information Classification Policy.
More precisely regarding “labeling” of information. I would like to stick as close as possible to the default document.
However, as a B2B communication agency almost all information we manage (and that is a lot) can be classified as “Internal use”.
Is it ok to specify that all “(unlabeled)” or “INTERNAL” labeled information is to be considered “internal use”?
So that we can avoid needing to label just about everything with the same label.
Could can an alternative be to use “(unlabled)” for “internal use” and “public” for “public” assets?
Which and too and approach can I use to make my asset inventory and risk analysis in order to see which control I need to put in place?
1. Regarding EU GDPR & ISO 27001 Integrated Documentation Toolkit:
Does it cover also ISO 27701:2019?
2. Does it cover also GDPR cases where EU customer personal data is processed outside of EU in a country like ***? (like using standard data protection clauses adopted by the EU Commission, etc?)
3. Does there exist an employee contract template which takes into account GDPR?
4. Does there exist a B2B contract template which takes into account GDPR when processing EU customer personal data in a country like ***?
5. Does there exist a B2B contract template which takes into account GDPR when EU customer personal data is processed outside of EU in a country like ***??
Do you have any thoughts on the ISO/IEC 38500?
Would we want to add this after our ISO/IEC 27001 that we are working on?
Also, in regards to the ISO 22301, does this compliment the GDPR that we are working on?