ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Information Classification

    We’ve got some questions surrounding the development of our information classification policy.

    The context is we are a three person company with literally tens of thousands of old documents spanning over a decade. Even the task of sorting through to purge  them ( which I actually don’t think we would want to) would probably be in feasible for us.

    My specific questions are:

    1 - Is there anything that would stop us from simply having two classifications Public and Confidential?

    2 - Assuming we adopted a mandatory classification protocol at an individual document level on say December 1. What would be the recommendation as to classification of all pre-existing documents

    3 - ...If the response is that every old document must  be classified this would be impossible for us. So therefore my next questions are around whether we can classify not at document level, but at a higher level.:

    4 - Would it be legitimate to have a classification policy at a document type level?

    5 - Or is it legitimate to classify based upon where the electronic document is stored (eg everything  in this Microsoft Teams channel is Confidential?

    6- Overall any general thoughts / advice you may have for creation of a workable classification policy for such a small company?

  • Classification of company assets

    Junto con saludarte, quisiera por favor si me pudieras ayudar con una duda que tengo. Estoy haciendo la clasificación de activos de la empresa y en el caso por ejemplo de los computadores y laptops, tengo que ingresar en la clasificación todos los que existen en la organización o sólo  uno?.

    Quedo atenta a tu respuesta, saludos y gracias

  • ROSI - interpreting calculated value

    Hi I wonder how I should Think when i calculate my ROSI value . If I receive a positive value I should invest in that security correction and if I receive a negative value I should not invest. Have I understood it right?

  • Isolation of Sensitive Systems

    I would like to request for your comment or idea on which I still doubt on how to check this point "Isolation of Sensitive Systems" - According to identified risks, do sensitive application systems operate in an isolated processing environment?

    I would very much appreciate for your kindly comment and any idea.

  • ISO 27001 certification for subsidiary companies

    Hi, We are considering going for ISO 27001 certification but we have a fully owned subsidiary company in the *** (we are *** based). 1 - Is it possible to certify the two together or is it necessary to seek certification for each one individually? 2 - Similarly would we need a separate ISMS for each?