ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • CFO exclusion from ISMS Scope

    I’d appreciate your help/reassurance on a query regarding our ISMS scope.

    Context

    For our ISMS scope, I have added in an organisation chart. On the basis of your advice stating that 3rd parties are out of our remit of control I have made our CFO (he is an independent consultant) and shareholders out of scope.

    Question.

    In the section, exclusions from scope, are we okay to exclude the CFO/Finance function and shareholders from the scope?

    Thank you in advance for your guidance on the above,

  • Example of a completed Risk Assessment Table

    Do you have an example of a completed Risk Assessment Table I could look at please. I am interested particularly in the numbering system. It seems to me the numbering should run by asset not by vulnerability, so 1.1, 1.2 etc until next asset.

  • List of documents for BCMS

    Es factible contar con una lista de documentos secuencial solo para SGCN.
    Te comento que actualmente ya contamos con un SGSI implementado e iniciaremos en breve la implementación de nuestro SGCN. Respecto a los documentos, adquirimos el paquete completo para que nos ayude a complementar el SGSI que actualmente tenemos.

  • Setup of Governance, Risk and Security department

    I have been tasked to setup the IT Governance, Risk and Security department from zero and was wondering what approach to take to make it easy to adopt as well as practical being practical and allow me to introduce polices, guidelines to mitigate risks as I go along.

  • Which are the right ISO standards to use

    I would like your guidence in which standards are the right to use in respect of service continuity management. I find as well 27001 as 27301 and 27031 all relevant on top of 22301 for business continuity mgmt. Please let me know how you see which of these are most right to relate to as the primary - or if you find it relevant to look after more than one.

  • Reputation Management ISO product

    Question please, what is the status of the Reputation Management ISO product?

  • Closed the minor NC for last year

    Hi! I wanna ask something. What is the client already closed the minor NC for last year? However this year we still find the same issue. Is it minor or major?