ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Surveillance audit

    We'll have the first surveillance audit in the next 3 months. Finished our Internal Audit a month ago. I just join the team as a Risk&Compliance Manager. How to we prepare for tbe Surv.Audit? I'd like to have an activities plan, kind of a checklist for preparation.

  • NIST framework

    I am working on a project to provide an easy to use yet comprehensive approach for supporting boards to monitor their cyber risk responsibilities. We are thinking of using the NIST framework as a base because of it simplicity and fitting a set of best practices around it. You do such a great job of simplifying the complexity of ISO.  Is there a slimed down set of practices based on ISO standards we might consider? Thanks!!!

  • Processes in Risk assessment vs. business impact analysis article

    Regarding the Risk assessment vs. business impact analysis article, at https://advisera.com/27001academy/knowledgebase/risk-assessment-vs-business-impact-analysis/, what kind of processes do banks need to perform in 12 hours that would be unacceptable?

  • General Information Security Policy

    Anteriormente con la ISO 27001:2005 utilizaba la política general de seguridad de la información y ahí mismo definía el alcance y lo montaba en un manual de políticas, separando la política de seguridad, hoy veo que hay que hacer un alcance del SGSI, lo que me queda duda si debería ser tres documentos, Política General de Seguridad de la Información, Manual de Políticas ( Todo un set ) y el Alcance del SGSI por separado.

  • LGPD and ISO 27001 conformity

    Good afternoon, I read several articles on the site. I am graduating from the IT Security course.
    I would first like to congratulate you for the article on ISO 27001. And second, ask for a material tip for analyzing the development of the theme of my LGPD and ISO 27001 TCC implementation.
    Thank you very much in advance

  • LGPD e ISO 27001 conformidade

    Boa tarde, leio vários artigos do site. Sou Graduando no curso de Segurança em T.I.
    Gostaria primeiramente parabenizá-lo pelo artigo sobre a ISO 27001. E segundo, pedir uma dica de material para análise do desenvolvimento do tema do meu TCC LGPD e ISO 27001 implementação.
    desde já agradeço.

  • Corrective action in ISO

    In the templates, you provided us, in 12 procedure for corrective action, there is nothing in the document on preventive actions, is that no longer an ISO requirement? The only thing in there is corrective actions, this is also reflected in the 12.1 form

  • List of Legal, Regulatory, Contractual and Other Requirements

    I assume that for each company other/different requirements are relevant. Right?

  • Number of controls for audit

    1 - One initial question I have is whether there is a “required” number of controls that need to be audited for a certification?  I was thinking that an auditor would check 15-20 randomly selected controls? 

    2 - Any thoughts or recommendations for how best to approach this would be helpful and appreciated!

  • ISO 27001 Control

    1. I wanted to know how we can measure the maturity of an ISO control when trying to assess its maturity level with something like CMMI.

    2. How can we measure how effective is a control and how mature? Any resources that can help?