Could you give me a sample of assessment table for middle range organization?
Scope definition
Es cierto que una empresa puede certificarse en ISO 27001 sólo en una parte de la organización?, es decir por ejemplo sólo el área de Sistemas?
ISO 27001 systems audit
I would like to know a little about systems audits on how control domains are evaluated and what does each control domain consist of")
Implementing ISO 27001
I'm planing to implement ISO 27001 to a friends company that is a Security Guards company. He want's to get certified and be a pioneer, but i dont know how to apply the ISO on his specifics. Can we apply any point for physical guard security on the ISO?
Audit questions
A quick two questions, if I may. I have an argue with the certifier (which in the end is always right…)
Employee private devices
Should we include the (private) devices (mobile phones) of our employees in the asset register? In the scope document we have referenced that all assets in the asset register are within the scope. The employees access e-mails via the outlook app and therefore have information of the company on their devices. Is there any up/downside to adding the mobile devices? It would be around 20 devices.
Career on information security
I can't find any middle & big companies regarding ISMS then how can I start my carrier in ISMS ?
Media and assets
I'm just an information security management student. And I have a questions about the ISO 27001. Sometimes in the ISO 27001 they talk about media and sometimes about assets. Like the disposal of media and removal of assets. What is the difference between " media" and "assets"?
Risk management
Un consultor en temas de riesgos a quien apoyo con temas de seguridad informática (material del que soy su cliente) me pide que le colabore con aportes para incluir en su temario sobre GESTIÓN DE RIESGOS EN LA ERA DIGITAL. Les agradezco si tienen informacion que me puedan compartir.