I have a new job as Information Security Officer in a startup company in XXXXX. They are preparing for ISO 27001 certification since last year. Last month, we had Audit stage 1 but with one major con conformity and others minors ones. The major one is related with the measure of ISMS. Can you guide me how to do it?
Incident management procedure
In that part of the document my question is: "Management of records relating to this document“
Cloud Services Agreement Guidelines
I noticed that the SOA (cloud version) mentions a doc called "Cloud Services Agreement Guidelines" a few times. I cannot find that document in any documentation kit.Is it an actual document?
Internal audit
1. Hello I struggle to close this NC 12.8 Review of information system. Do you have samples of:
Certification bodies
Do you have a list of audit companies that are familiar with cloud based assets?
ISO 27001 toolkit content
I am currently working intensively with your premium package and I am missing vital parts of the ISO 27001 appendix controls:
SWOT Analysis and ISO 27001
We are ISO 9001: 2015 certified and we have already performed a SWOT analysis. Can we use this SWOT analysis for ISO 27001 or should the SWOT be more focused on security aspects?
ISO 27001 implementation
I only have a question but not about the ISMS scope because I was told by my friend that if I don't have any knowledge about Project management and business analysis at all, that ISO 27001 will be difficult for me to understand. He said in ISO 27001 there is a part you have to implement a project and if I don't know anything about PM and BA I can't do that. So my question is must I have a knowledge about PM and BA before any ISO?
Information Security Objectives
Does ISO 27001 prescribe a minimum amount of information security objectives? This is regarding the Information Security Policy and the Measurement Report.
Toolkit content
1. If I understand correctly, your premium package refers to the version of 2013? When can I expect an update to the 2017 version?