ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Security levels to have in the company

    What are the security levels to have in the company, type initial, medium, advanced? We are implementing information security in the company, and I need to know and understand how the security levels work and what do I need to have to reach each level? Can you help me with information?

  • Defining Scope

    How to define The ISO27001 Scope. I'm working for a hybrid company (~300 employees), 8 global locations, we offer cloud management services, and it's difficult to properly define the Scope.
    What should be included in the Scope?

  • Information security in project management

    I was wondering what information security in project management means practically. I am thinking that information should be protected by ensuring least privileged access rights, physical access security, etc - would this be a correct analysis of this control please?

  • ISO 27001 Lead Auditor course

    Hello. I am an IT Auditor on my previous job and currently i am a security compliance. I want to take CISA then after passing, i will take ISO 27001 Lead Auditor. Do you think this two certifications are good? or should I take ISO 27001 Lead Auditor certification only? I just want to hear comments from the expert. :) In addition, I want to focus my career path on audit but on the side of security.

  • Integrated implementation of ISO/IEC 27001:2018, ISO 9001:2015 and ISO 22301:2012

    can you please advise on what is involved in doing an integrated implementation of ISO/IEC 27001:2018, ISO 9001:2015 and ISO 22301:2012?

     

  • Security levels to have in the company

    Quais são os niveis de segurança para se ter na empresa, tipo inicial, medio, avançado?
    Estamos implantando a segurança da informação na empresa, e preciso saber e entender como funciona os niveis de segurança e o que preciso ter para alcançar cada nivel?
    Consegue me ajudar com informação?

  • BCP Framework following ISO 22301

    I need to craft out the BCP Framework following ISO22301 standard for critical IT systems, how do go about doing that?

  • Certified ISO auditor in the US

    I have an easy question for you. I am new to ISO anything. I like the way the framework is laid out. I have heard this framework (ISO 27000) is primarily used in Europe. I know ISO was started as a British standard, but is there a need to be a Certified ISO auditor in the US? Are American companies using or have to be certified under ISO? Since I live in the US, I am just wondering if it will help my career to take training and get certified.

  • ISO 27001 implementation

    How to install and what roadblocks they have experienced that delayed, or stopped, implementation

  • Risk Statements

    Hereby a question on how to write good risk statements using the known ISO risk component from 27005, Annex D (Threat, Vulnerability). Various articles (e.g. ISACA) highlight a risk statement on the formula: [Event that has an effect on objectives] caused by [cause/s] resulting in [consequence/s]. Can that in the ISO world be translated into: Threat (that has an effect on objectives) caused by a vulnerability resulting in a business consequence. So taking 27005, Annex D, the first row in the table, the Risk Statement will be: There is a risk of "breach of information system maintainability" due to "insufficient maintenance installation of storage media." This may lead to XWY. Or is it the other way round. That the risk is the "vulnerability"???