ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Information Security Incident or Business Continuity Disruption

    If a customer has a business continuity disruption that affects the availability of information, must they log it as an InfoSec incident AND a BCMS Disruption?  How should they go about assessing which system to manage it under?

  • List of referenced risks and numbers

    )n the example of the Risk Treatment Plan used in the ISO 27001 online training, there was mention of reference to risks like:-
    Risk no 16. Unavailability of electronic records due to accidental loss.
    Risk no 32. Laptops could be stolen by external persons.
    How do I get a list of this referenced risks and numbers?

  • Key elements of ISO 27001

    he Ministry of Justice is requiring ISO27001 of the charities providing resettlement services, some as small as £100k turnover.

    I have been asked, for tomorrow, to explain it to them. What are the key elements that I could explain in 5 minutes?

    Looking online i see a lot about process and reports, not much about what technology they have to have in place.

    Hope you can help!

  • Main challenges in the implementation of ISO 27001

    What are the main challenges in the implementation of ISO27001?

  • Information Security Management System

    Aconsejaría (viable) y que recomendaciones daría durante o posterior al diseño del SGSI se desarrolle una aplicación para realizar una gestión y seguimiento automatizado y adecuado de la seguridad de la información, con una trazabilidad al implementar un Sistema de Gestión de Seguridad de la Información (SGSI)?
  • How to inspire people for new standard?

    How to inspire people for new standard (their work is longer after iso and they need to document doings, get tickets for passwords, have DLP etc.etc.)

  • ISO 27001 Asset Management and Information Classification

    Could you please clarify the relation between having Asset management process in place and Information classification policy. - Our Assets (Laptop, Desktop, Servers and SW license) and we have defined the full cycle in the process - Our Information classification is mainly for documents and processes (Confidential, Restricted, Internal use) Thus I would appreciate it if you can explain/clarify the following points: - Do we need to classify our Assets or label it as (Confidential, Restricted, Internal use) or do we need to add another category for assets - Do we need to classify the info on Assets !! but if Laptop (as an asset) has documents confidential and documents restricted ? in this case laptop as an asset Is considered to be confidential or restricted ?
  • ISO 27001 Certification

    Please what is the difference between PRACTITIONER vs lead implementer iso 27001 certification

  • Scoping an organisation to be ISO 27001 certified

    How do you scope an organization to be iso27001 certified?