Implementing regulatory requirements against cyber-threats
I am a student at University of Cape Town, studying Compliance Management short course. We have to discuss the topic Implementing regulatory requirements against cyber-threats. What are some of the key points I must focus on?
Mandatory and non-mandatory documents
I'm a collage student and now I'm doing my undergraduates thesis about risk management with ISO 27001 controls as the mitigation guide. Or maybe it can be said ISMS planning. I have analyzed risks and got some high level risks that need to be mitigated. But the problem is I don't understand about ISO 27001 mandatory documents. How can we define the mandatory document for our planning or we have to do all the document list? Is it explained in ISO 27001 Information technology - Security techniques - Information security management systems - Requirements document? Can it be adjusted with the ISO 27001 control that we have chosen?
Physical access controls
I was searching your site but could not find a dedicated article. Is there any white paper / link regarding ISO demands for controls etc for access to physical premises (buildings, floors, rooms?)
Questions about assets
Is the course enough for certification?
Seeking confirmation that your course will be all we need to get ready for ISO 27001 certification and to understand work involved.
Is Inventory of assets a document or a record?
Can you please help me understand why "Inventory of assets" is listed as a mandatory ISO 27001 "document" instead of "record" on this page
How to become a consultant in ISO 9001, ISO 22301
How to become a consultant in ISO 9001, ISO 22301?
Best practice for BC Plans
Can you recommend a good site, book, etc as to best practice for BC Plans?
How to develop and implement DR Plan
How to develop and implement DR Plan for my organisation?
ISO 22313 and BCMS implementation
95/5000 Where does the ISO 22313 guide for the adoption of ISO 22301 support me? How much value does it give me?