Guest
hi. is the 4 years experience in IT mandatory prior taking up ISO27001?
I have a question about SoA and selection of controls:
If control is selected as applicable in which extent the control is required to implement?
For example: if control A.9.4.3 Password management system is selected as applicable is it required to implement to every single system/application in the Company or is it enough to implement it according to assessed need (based on assessed risks and other relevant information concerning the systems/applications)?
What would be the consequence for non-compliance?
I was asked today if ISO Lead Auditors must be recertified annually. I do not recall that requirement from the Lead Auditor training/certification nor can I find anything online that would indicate recertification is necessary. However, HITRUST CSF Practitioner does require recertification and refresher courses, so it would seem reasonable that BSI or Exemplar would also require recertification/refresher courses.
How to protect against external and environmental threats according to ISO 27001. and what are the steps that I need to consider? A.11.1.4
I am a little confused on the SOA document, this document is suppose to directly reference the Annex A controls, in the SOA it says
There is no a.5.1.1 in the annex A controls I have, also 6.1 in the SOA talks aboutInformation security roles and responsibilities. where did that come from in Annex A controls? I just have BYOD and mobile device policies.
I want to know what are the records that need to be collected for physical access audit?
Kindly provide me with the key universal principles of segregation of duties with their explanations.
I want to know if ISO 27001 internal auditor is better for me or lead auditor. I have already completed 200+ remote audits. Just want a certification to support.
I attend the ISO 27001 Lead Implementer Video training course and I want to know is the training contents designed by Advisera or by standard bodies as BSI or PECB. I noted that the whole course explaining project management approach for implementing the standard more that a security related project. My question for the instructor “ is this training will help me to pass the BSI or PECB ISO 27001 Lead Implementer exam or it is designed only for Advisera?