ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Process diagram

    1. I would like to know if there is an excel template to register a new change.

    2. And the other thing is about the process diagram. I believe it is essential for that document.

  • ISMS scope - Networks and IT infrastructure

    I just started to look into your ISMS scope template and video but 3.4 Networks and IT infrastructure not explained your video tutorial.

    About my company: It's a *** based software development company (mobile apps and web development) and around 15 employees working in my company.

  • 5.1 Leadership and commitment

    1. What Template in our Toolkit contains this Clause?

    2. Can we be compliant with this clause maintaining our Information Security Policy? If yes, what shall we give emphasis on apart from company Policies and guidelines?

  • A.18.1.3 Protection of Records

    Does the Topic Protection of Records limit to the protection of ISMS documents only? If not, then what other Records of the Company needs to be protected and please suggest some ways of protecting it.
  • Implementation of ISO 27001

     Do you have a template for a copyright protection policy to meet the requirement of Annex A.18.1.2?

    In your pdf list of documents, you point out that A.18 does not exist as a separate folder, but the content for it can be found in the following folders:

    02 - Requirements identification process
    08, A.8 - Management of values
    08, A.10 - cryptography
    Unfortunately, we cannot find a template for a guideline for A.18.1.2 in these folders

    Can you please help us here and contact an expert?

  • Pricing a consultancy

    I am new at Consulting but have been a business continuity manager for a large international financial institution for over 15 years until they moved their operations to *** in 2017. I hold the CBCP and ARMP certifications from DRI.

    I am in *** and the market is small. How would you go about pricing a consultancy to prepare a business continuity plan for a small trust company that has 8 employees?
    I would prefer to do the costing as a project rather than an hourly rate. Would appreciate your guidance.

  • Equipment Sitting and Protection A.11.2.1

    According to your list, nothing is missing but looking at the standard under physical and environmental security policy there is Equipment Sitting and Protection A.11.2.1 not in the pack?

  • Backup policies

    Would ISO 27001 verse about systems (and workstation) backup policies? I have a call for laying down a corporate backup policy and hence, I'm looking for an ISO standard aligned template. Should ISO 27001 is not the right standard for that, which one should I seek?

  • Question about documents

    1. Most incoming documents, contracts, etc would be online. However, if they were to be paper only, how do we handle these?  Can we just scan?

    2. Also, what if an employee were to print a document?  Should we note that they are responsible for ensuring they are always referring to the latest version and that they must shred when a new one is available?

  • IT Resilience Requirements

    I am building an IT Resilience Requirements for IT and for Projects and I would like to make it comprehensive please help me with a guide or template thank you regards