ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Access control

    Today I consult a large institution, where we are equalizing control systems of logical and physical access, I am in search of content about physical access (standards, good practices, axes of analysis, premises), but it is a very complicated content to achieve .
    Do you have any indication of content?

  • Access control

    Hoje presto consultoria a uma grande instituição, onde estamos equalizando sistemas de controle de acesso logico e fisico, estou na busca por conteudos sobre acesso fisico (normas, boas praticas, eixos de analise, premisas), mas é um conteudo bem complicado de se conseguir.
    Voce teria alguma indicação de conteudo?

  • Implementing ISO 27001 in a greenfield

     sincerely hope my email finds you well and safe. Just want to pick your brain about implementing an ISMF in a greenfield site.

    1 - What are the key considerations when implementing an ISMF such as the ISO 27001 in a greenfield site – i.e. an organization where there are nothing in terms of security policy or practice. Would we go through the normal workflow of implementing ISO 27001 or are there deviations?

    2 - Can you suggest any additional resources I could use for greenfield implementation?

  • Information Classification

    We’ve got some questions surrounding the development of our information classification policy.

    The context is we are a three person company with literally tens of thousands of old documents spanning over a decade. Even the task of sorting through to purge  them ( which I actually don’t think we would want to) would probably be in feasible for us.

    My specific questions are:

    1 - Is there anything that would stop us from simply having two classifications Public and Confidential?

    2 - Assuming we adopted a mandatory classification protocol at an individual document level on say December 1. What would be the recommendation as to classification of all pre-existing documents

    3 - ...If the response is that every old document must  be classified this would be impossible for us. So therefore my next questions are around whether we can classify not at document level, but at a higher level.:

    4 - Would it be legitimate to have a classification policy at a document type level?

    5 - Or is it legitimate to classify based upon where the electronic document is stored (eg everything  in this Microsoft Teams channel is Confidential?

    6- Overall any general thoughts / advice you may have for creation of a workable classification policy for such a small company?

  • Classification of company assets

    Junto con saludarte, quisiera por favor si me pudieras ayudar con una duda que tengo. Estoy haciendo la clasificación de activos de la empresa y en el caso por ejemplo de los computadores y laptops, tengo que ingresar en la clasificación todos los que existen en la organización o sólo  uno?.

    Quedo atenta a tu respuesta, saludos y gracias