Guest
I have some questions regarding 27001 implementation.
1 - In the datacentre we run there is a service called Remote hands, in which customers having their equipment there under a regime of colocation, meaning we have no logical access to data, we may do some wiring, etc. I know that other similar companies leave this service out of the scope. I understand this is the correct approach, but can you give me a good justification for this?
2 - In our Spanish office (not the datacentre) we have a person who is a relative of our boss, whose activity has nothing to do with the company but he acts as a contact person for some administration duties. He shares a connection to the internet with us but we set up a separate VLAN so he can´t access our networks. Of course, he has physical access to all resources in this office. Should we leave him out of the scope or otherwise include him?
3 - We have an extensive asset inventory that we use to calculate amortization but the woman in administration refuses to give me a copy so I can include it in the documentation. Management is not supporting me with this because this woman is not easy to deal with and no one wants to fight her. Any solution? Is it mandatory to have the inventory as a separate document in the IS system or we can refer to it as it is now?
4 - Security records. What happens if we don´t have any (as such format) prior to the certification audit?
5 - Legal requirements doc: should all customers be listed? How often should it be updated then? Can we refer this item to our CRM software?
Do have any advice for implementing ISO27k into an existing ISO13485 certified QMS?
How business continuity management is represented in the ISO 27001 track and if these business continuity practices can be joined with those from other standards (like the BIR 31111 & ISO 22301 ) in order to come up with the best practices for BCM?
I have over 12 years of experience in ITES in Infrastructure Services including recent 5 year's experience in the eDiscovery domain. I am currently working as an Assistant Manager and would like to move my career to Information Security domain and also seeking for next level position as well in my current org. I would like to know which certification would help me to grow ISO 27001 or CISM.