1. Hello I struggle to close this NC 12.8 Review of information system. Do you have samples of:
Certification bodies
Do you have a list of audit companies that are familiar with cloud based assets?
ISO 27001 toolkit content
I am currently working intensively with your premium package and I am missing vital parts of the ISO 27001 appendix controls:
SWOT Analysis and ISO 27001
We are ISO 9001: 2015 certified and we have already performed a SWOT analysis. Can we use this SWOT analysis for ISO 27001 or should the SWOT be more focused on security aspects?
ISO 27001 implementation
I only have a question but not about the ISMS scope because I was told by my friend that if I don't have any knowledge about Project management and business analysis at all, that ISO 27001 will be difficult for me to understand. He said in ISO 27001 there is a part you have to implement a project and if I don't know anything about PM and BA I can't do that. So my question is must I have a knowledge about PM and BA before any ISO?
Information Security Objectives
Does ISO 27001 prescribe a minimum amount of information security objectives? This is regarding the Information Security Policy and the Measurement Report.
Toolkit content
1. If I understand correctly, your premium package refers to the version of 2013? When can I expect an update to the 2017 version?
ISMS
La TI misional de una compañía se administra (desarrollo, operaciones, soporte) por un tercero, para el que esta operación significa el 90% de su negocio. Se ha tomado la decisión de adquirir esa compañía, que está certificada Iso 27001. La compañia principal tiene su propio Sgsi, pero con criterios, metodologias, procedimientos diferentes. Se necesita “mantener” el certificado vigente. Cuales podrian ser las alternativas para adoptar/ajustar/integrar los sgsi? Cual puede requerir menos esfuerzo? Cual podría ser menos riesgosa (perder el certificado)?
Handling nonconformities
I'm creating an action plan in order to close some NC found during the audit, what is the document that I have to fulfill in order to close the NC, the point is D.6 6.2 Information Security in projects?
ISO 27001 implementation project
I've been tasked to co-ordinate an ISO 27001 implementation project at my company and i had a few brief questions.