ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Experience for taking up ISO27001

    hi. is the 4 years experience in IT mandatory prior taking up ISO27001?

  • SoA and selection of controls

    I have a question about SoA and selection of controls:

    If control is selected as applicable in which extent the control is required to implement?

    For example: if  control A.9.4.3 Password management system is selected as applicable is it required to implement to every single system/application in the Company or is it enough to implement it according to assessed need (based on assessed risks and other relevant information concerning the systems/applications)?

  • Question about non-compliance

    What would be the consequence for non-compliance?

  • ISO Lead Auditor certification/recertification

    I was asked today if ISO Lead Auditors must be recertified annually.  I do not recall that requirement from the Lead Auditor training/certification nor can I find anything online that would indicate recertification is necessary.  However, HITRUST CSF Practitioner does require recertification and refresher courses, so it would seem reasonable that BSI or Exemplar would also require recertification/refresher courses.

  • External and environmental threats

    How to protect against external and environmental threats according to ISO 27001. and what are the steps that I need to consider? A.11.1.4

  • Annex controls in SOA

    I am a little confused on the SOA document, this document is suppose to directly reference the Annex A controls, in the SOA it says 

    https://www.screencast.com/t/hx3EjFzq

    There is no a.5.1.1 in the annex A controls I have, also 6.1 in the SOA talks aboutInformation security roles and responsibilities. where did that come from in Annex A controls?  I just have BYOD and mobile device policies.

  • Physical access audit records

    I want to know what are the records that need to be collected for physical access audit?

  • Key Universal Principles of Segregation of Duties

    Kindly provide me with the key universal principles of segregation of duties with their explanations.

  • ISO 27001 Internal Auditor or Lead Auditor

    I want to know if ISO 27001 internal auditor is better for me or lead auditor. I have already completed 200+ remote audits. Just want a certification to support.

  • ISO 27001 Lead Implementer Course

    I attend the ISO 27001 Lead Implementer Video training course and I want to know is the training contents designed by Advisera or by standard bodies as BSI or PECB. I noted that the whole course explaining project management approach for implementing the standard more that a security related project. My question for the instructor “ is this training will help me to pass the BSI or PECB ISO 27001 Lead Implementer exam or it is designed only for Advisera?