If my supplier holds ISO 27001 certification, do I need to perform risk assessment on it?
ISO 27001 and ISO 22301
If my company does not have server and we did not implement ISO 27001, possible for us to get ISO 22301? I have no idea how to do BIA if without ISO 27001.
Lead Auditor or Lead Implementer
I got a new job opportunity, and it one of the tenders the customer requested compliance with ISO 27001, so before moving I'm planning to learn more and maybe get an accredited certificate.
BS25999 and ISO 22301
I have seen that your isms toolkit still refers BS 25999 in addition to isolate 22301. Is there any specific reason?
Confidentiality level of a document
Would you mind telling my what level of confidentiality the "policy for the use of cryptographic measures“ usually has?
Difference between Risk Treatment Plan and Corrective Actions
Hi, I'm not clear on why we would use 2 different documents for how we treat a risk identified and using the corrective action form. Can you give me examples so I can see the difference when they're used?
Performing risk assessment
Hi I follow your articles diligently all of them; big admirer of your know how. One topic I couldn't find detail was actually doing Risk Analysis. Issue is when we do RA, we have defined Assets and then put owner and then C I A value; in assigning CIA values for different assets, would it be done based on value of that asset to company or threat marked for that asset. Which method would be correct, as I haven't seen any article anywhere explaining this. If it is based on value of that asset to company then chance is CIA markings for a asset would be same for different threat for a company, would it be correct?
Questions about risk assessment and treatment
Last year I bought ISO 27001 package to implement a ISMS for a customer. I Used all the documentation but the auditor wants to know the risk analysis method used( méhari? Ébiseler? Etc....)
Assets for risk assessment
Could you give me a sample of assessment table for middle range organization?
Scope definition
Es cierto que una empresa puede certificarse en ISO 27001 sólo en una parte de la organización?, es decir por ejemplo sólo el área de Sistemas?