ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Supplier compliance

    I have a supplier with an office in the UK but its main offices are in the US. They have an ISO27001 certificate that doesn’t include their UK office, is the UK office compliant?

  • Signature in the Advisera's Documentation

    Is it necessary to sign each and every Template after filling the Org related info in Advisera Templates or we can delete this section.

  • ISMS risk calculation

    I would like to know what standard is the risk calculation for ISMS, please?
    I want to know what standard iso-27001 use for risk determination, or risk calculation.
    Actually what documents explain step by step to risk calculation in an enterprise

  • Policy for secure development

    I have a question about the Policy for safe development. The policy talks in chapter 3.4 about control A.14.1.1.The reference documents above do not include the control. Can I add control A.14.1.1 to the reference documents and the policy for safe development also as the implementation method for control A.14.1.1 inside the SoA?

  • Procedure for measurement

    I was wondering if there should be a procedure for measurement of the ISMS in the ISO 27001 documentation package. I don‘t seem to find it.

  • RACI Matrix

    f I have a policy with certain users. Are these users the „responsible“ in a RACI-Matrix or will they only be the „informed“ ones which must comply with the policy?
    Would the „responsible“ person, in that case, be the person who wrote and maintained the policy? Or would both fall into the category „responsible“?
    My specific case is the „policy for safe development“. In that case, our programmers and system administrators are the users of this policy. Are the programmers and system administrators, in that case, the responsible people or just the informed ones that these policies exist and that this policy must be followed?

  • Policy for use of cryptographic

    Requiero un asesoramiento sobre como debe documentarse las políticas sobre criptografia. Esto para llegar a una certificación de ISO 27001.

  • Auditor costs

     Do you know how much usually ISO auditors likely cost?

  • Assets in the cloud

    When developing the policy for our inventory of assets, the question came up around how do we inventory ephemeral assets in the cloud? Some servers are spun up when the extra compute is needed, then they are torn down automatically and are gone. Do we need to account for those somehow as well?

  • ISO 27001 and NESA requirements

    Is ISO 27001 a prerequisite to comply with NESA requirements