Guest
Is it typical in smaller companies (50-100 employees) that for the internal audit an external auditor is being hired? Or should you be thinking of somebody internally in the first place anyhow?
1. I'm reading the Business continuity Policy according to ISO 22301; I Don't understand why it is written, "Because in many cases the executives have no idea how business continuity can help their organization, which means they won’t be particularly interested in supporting the business continuity effort in their company."
How it can be possible?
2. If they are not involved that plant will be closed?
Hello, I am having a hard time understanding the difference between BCP and DR. I know for our ISO cert we have to include a.17.4.6 right? That is the Disaster Recovery Plan, but our certifier is saying we do not have to complete the Business Continuity Plan, which is the rest of a.17, why is that?
Many thanks for offering the Lead Auditor ISO27001, I was wondering if one has to start an audit, is there any process chart that can be used as guide ( like a flow chart )
Define Scope --> Review ISP and related documents --> Perfrom SOA --> etc
Something similar to Diagram of ISO27001 Implementation process but for conducting an audit
Cheers
Alex
Whilst attending your ISO/IEC 27001 Lead implementer course, the following question (which actually consists of two subquestions) has arisen:
After risk assessment (in which I have considered also already implemented controls in order to reduce likelihood and/or impact) I still have a small number of unacceptable risks (i.e. with high-risk level).
Now I have to choose between available risk treatment options. I decide to apply further controls (although I think I could also choose risk acceptance as a risk treatment option and as a result to simply live with risks due to my risk appetite). I pick up 2-3 applicable controls (although there are more applicable controls in Annex A which I do now wish to adopt) from Annex A which will be implemented in the risk treatment plan later on.
First subquestion: Is my thinking process aligned with ISO/IEC 27001 requirements?
Second subquestion: I now have to create the statement of applicability. Can I only consider (in the SoA) those controls which I have considered as significant for reducing my unacceptable risks OR is it mandatory to implement also controls (from Annex A) which I regard (according to my opinion) as not really useful or which I simply do not wish to apply?
One question I had in regards to the security clauses was, how does the ISO 27001 ensure us data integrity?
I will be working on the ISO 27001 for *** together with my colleague, and we are having trouble with dividing the workload between us. Every document in the package, and every corresponding clause in the norm, seems to be an extension of the preceding one. The formulation of the policy, for example, has to be built on the definition of the scope. This makes it complicated to work on the documents and clauses separately. Do you have any tips or advice on this issue?