ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Control A7.1.1

    Control A7.1.1 is partially applied to Brazil under the law. In this case, can I put NO in the SOA and explain this or do I have to put YES and explain the exceptions?

  • ISO 22301 planning phase

    Element of iso22301 that need to be considered in planning phases

  • ISO 27001 exam

    I am your student at Advisera and just started going through the course now. So far it has been a great experience. Any possible way I have to leave a feedback, I am happy to do so.

    Very soon, I am expected to take the Lead auditor exam and sort of lost now as I am unsure which exam I should take. My key requirements are that I need to take iso 27k1 LA certification that is not very expensive and does not expect me to attend a mandatory training program (As I am planning to go through yours)

    I have been told for the PECB iso 27k1 exam, I need to attend their training and the same is the case for another one IGC.

    Based on your expertise and experience, can you please advice me on the following:

    1. Is there a significance in selecting the right body for certification. For eg. should i select Exemplerar/PECB/BSI compared to IGC (As IGC is perhaps not that well known) and does it have an impact on the CV.

    2. Can you please point me to the right exam provider that does not need me to complete the exam compulsorily and advice what is perhaps the best one (both from a cost and recognition standpoint)

  • Continuous Improvement

    How can we be compliant to this Norm Document?

    10.2 Continual Improvement

    Considering we are already complying to all the ISMS relevant Topics, do we have to make any separate Documentation of this or?  Since ISO calls for the Documented information, does Advisera Toolkit provide any Template for this?

  • Business Continuity Plan template

    What is the difference between:
    07 Business continuity plan and 17.4 Business continuity plan?

  • ISO 27001 in pandemic

    I wonder how (most) of ISO 27001 can be applied in a world where everyone is WFH. And that's before even thinking about the information security issues with all the SaaS everyone is suddenly dependent on (Zoom...)."

  • Question about policy

    Thanks for your continuous insight into Management Systems.
    I have 2 questions on my mind.

    1. Is there any document showing how to link policies? That is which policies are dependent on which policies?

    2. How to show risks of inadequate leadership in a nice way

  • Risk treatment plan

     If we have identified a control in the SoA that is a legal requirement or a management decision to implement, can I document the associqated tasks in the RTP or should I create a seperate spreadsheet to handle these?

     

     

  • Toolkit content

    which product has A.18. Compliance i stopped by yesterday to ask about this we have the toolkit but I don't think it inclues this one is there a different one which may?
  • A.12.6.1 Management of Technical Vulnerabilities

    Hi I'm a customer with a question - is there anything specific regarding patching in the toolkit that we purchased. I see that the ISO has a standard: A.12.6.1 Management of Technical Vulnerabilities but not sure there's this document in the toolkit