Guest
Can I use some useful 9001 procedures for 27001? Such as "HOW TO"?
I am very new to the world of IRM as it relates to cyber security. I am literally learning on the job.
Part of job spec involves drafting policies, procedures, and standards related to the security stance of various companies. I have next to no knowledge of ISO, i do have a copy of the ISO/IEC 27000:2014(E) i would like some input and guided walk through examples as a lot of the content flies over my head.
What are the prerequisites for the implementation of ISO 27001
I have a question to Assets Inventory:
When describing Software, should we go detailed and list every important software which we have, or just list that generally, grouping like in sample excel:
application software (licensed)
freeware; shareware
system software
various tools
databases
With regards to the Asset Name of ICT Equipment Maintenance in the Risk Assessment Table spreadsheet we purchased, should all ICT equipment be broken out individually in the risk assessment table? Or should they be called out in the Controls Document for th ICT equipment?
What is the best way forward to protect data/information both digitally and physically and when used in Artificial Intelligence modeling?
What are the risks for those working on a contracted cloud, such as Google Cloud Platform?