ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • ISO 27018 versions

    What's the difference between ISO 27018:2014 and ISO 27018:2019?

  • ISO 27001 new version

    Hello, I'm a legal counsel of the IT-company. We are going to implement ISO 27001. I have found the checklist and toolkit for 27001:2013. But I know that there is the newer version - 27001:2018. My question is: if we prepare all the documents and standards according to the requirements of the 2013 version, shall we be able to pass the certification? Thanks.

  • ISO 27001 certification process

    1. I am currently in the process of trying to get our company ISO 27001 certified. That being said, after going through your toolkit and getting all the document and policies in place, what would be our next step?
    2. Who is it that certifies us that we are ISO 27001 certified and provides the certification?
    3. I also see that you have a course for lead auditor, what is the benefit of this certification?

  • ISO 27001 and SIEM

    Me gustaria tratar el tema acerca de como integrar la ISO 27001 con la implementación de un SIEM, es decir, tengo claros algunos conceptos y algunas relaciones existentes, pero me gustaria fundamentar de mejor manera dicha integración y conocer mas acerca de la ISO 27001 para poder relacionarla.

  • Risk assessment process

    I wanted to find out which ISO 27001 output documents are to be made ready before the Risk Assessment process commences?

  • RTO and MAO

    Can the RTO be more than the MAO?

  • Risk Assessment software

     What software do you use for making the assessment process?

  • IS Manager role

    Please I will like to know the roles of IS Manager in any organization.

  • Document Control Procedure content

    In the procedure for document and record control doc, it says...

    “Each external document which is necessary for the planning and operation of the ISMS/compliance with GDPR must be recorded in the incoming mail register. The incoming mail register must contain the following information: (1) document number, (2) sender, (3) document name, (4) date of receipt, (5) name of the person to whom the document has been forwarded.”

    1. Is this something that is needed for ISO?
    2. How do I know which external documents are necessary for ISMS  compliance?
    3. Also is there an incoming mail register document as part of the templates?

  • Security awareness training

    Do you have any hint of what points to be taught in an awareness session to users?