Guest
So, I would like to ask you some questions about BIA:
This question is regarding document scope, especially as it pertains to section 3.2 Document Approval.
In our very small organization, all ISMS specific documents would be reviewed and approved by two individuals. That I understand, no problem. But for client work/project related documents that are created such as project plans, creative files, copy decks, etc., often times there is no review and approval process needed. Documents are created by the employee and sent to the client.
How would that be described in section 3.2? Do I describe an "exemption" for review and approval of client project work files?
I am using the vide tutorials to complete my documents downloaded. However they do not align completely. I am currently looking at the ISMS Scope tutorial and the document being used in this does not align with the document we have purchased.
In the file 00_Verfahren_zur_Lenken_von_Dokumenten_und_record_27001_DE.docx there is a comment from you "Delete if the declaration of applicability precludes measure A.8.2.1 according to ISO 27001." Where are the measures, I have to read the measures first so that I can exclude them?
We are discussing the ownership of general procedures. We have a classification of information in my organization and we are pretty much ISO27001 compliant. I, as an IT auditor, consider that the "head" of the organization is the owner of the general procedures, which are applied throughout the organization. Do you find it correct?
I really like your book as it is more detailed and clearly define the meaning. But I have doubt in one word "Risk Deviation" what does it mean? I do hope you could help me with the explanation on this?
1. Regarding Segregation of duties I believe some jobs can’t be combined (like the SO can’t be the DPO?)
2. Are there specific combinations that are not done? We have these roles in the company? To divide under 4 people:
Security officer (is also Risk manager & Authorization officer)
Internal auditor (external consultant)
Service manager (is also Change manager & Incident manager)
Security tester (outsourced)
Compliance officer
Solutions Director
DPO
3. Do you also have standard lists of the Responsibilities & Requirements of these roles?