Guest
I'm on a tight deadline to write a Disaster Recovery policy that is compliant with ISO/IEC, HIPAA, NIST, and SOC 2, maybe some others.
1. Do you have any suggestions for me?
2. What other ISO standard is associated with the ISO/IEC 27001 and 27002?
Can you share me the of what is the difference between ISO27001 AND NESA?
Buenos dias, como ya sabeis, compre el paquete de documentos para 27001 y 22301.
Desde octubre, ya esta disponible la version 22301 2019, me podeis confirmar por favor si teneis previsto actualizar los documentos que han variado o si por el contrario, se quedara en la version comprada?
A.9.1.1 Access control policy control
I have a supplier with an office in the UK but its main offices are in the US. They have an ISO27001 certificate that doesn’t include their UK office, is the UK office compliant?
Is it necessary to sign each and every Template after filling the Org related info in Advisera Templates or we can delete this section.
I would like to know what standard is the risk calculation for ISMS, please?
I want to know what standard iso-27001 use for risk determination, or risk calculation.
Actually what documents explain step by step to risk calculation in an enterprise
I have a question about the Policy for safe development. The policy talks in chapter 3.4 about control A.14.1.1.The reference documents above do not include the control. Can I add control A.14.1.1 to the reference documents and the policy for safe development also as the implementation method for control A.14.1.1 inside the SoA?
I was wondering if there should be a procedure for measurement of the ISMS in the ISO 27001 documentation package. I don‘t seem to find it.
f I have a policy with certain users. Are these users the „responsible“ in a RACI-Matrix or will they only be the „informed“ ones which must comply with the policy?
Would the „responsible“ person, in that case, be the person who wrote and maintained the policy? Or would both fall into the category „responsible“?
My specific case is the „policy for safe development“. In that case, our programmers and system administrators are the users of this policy. Are the programmers and system administrators, in that case, the responsible people or just the informed ones that these policies exist and that this policy must be followed?