Guest
Hi, I wonder if you can share views or references regarding ISO 27001 compliance efforts for companies adopting Agile SCRUM for software development. I'd love to know as well from ISO 27001 auditor's view on that.
I found a simplified security policy which encapsulates a lot of the policies provided in the tool kit but at a higher level. Would something like this be appropriate for our implementation of ISO 27k and would it be appropriate for an audit?
Boa tarde, gostaria de saber em qual norma informa a distância recomendada entre sites de redundância e qual seria essa distância de segurança?
(Good afternoon, I would like to know which standard tells you the recommended distance between redundancy sites and what would be this safety distance?)
For clause 7.3 of the ISO 27001 standard, it is required to ensure employees are aware of the information security policy, as well as their role and consequences of not complying. Is this covered through the document template "Statement of acceptance of ISMS"?
How do you verify compliance to regulatory requirements? It should be a scheduled audit or random verification of meeting criteria? Thank you for consideration.
I have implemented ISO27001 at a country level. The Global company was only an interested part as a shareholder. But now that has changed and they are wanting to manage the network at a global level.
I don't know how to treat them in as part of this certification. Could you help with some advise on how to treat them?