The Statement of Acceptance of ISMS System Documents
The Statement of Acceptance of ISMS System Documents. Can you please supply a consolidated list of policies the auditor requires each employee to sign for?
Templates identification
I recently purchased the ISO 27001 Toolkit. I see on your website (which is great, BTW) the Acceptable Use Policy for purchase and it appears to be identical to the IT Security Policy that ships in the Toolkit. Is one name preferred over the other? Our customers tend to ask for our Acceptable Use Policy, so I’m inclined to call it that. Would there be any reason not to?
Audit scope
My ISO 27k certification auditor is asking to audit one critical service provider (internal service in the company), this will be part of the surveillance audit . Is he authorized to do so?
I do have a question on BYOD – what is required by the ISO 27001 standard? And is there any guidance you can provide?
Roles and responsibilities
I have been going through the documentation. Under A6. Organization of Information Security there is no template for ISMS roles and responsibilities but just the BYOD policy and Mobile device and teleworking policy. Would you share a template for Roles and Responsibilities if you have any?
Physical security
1. I would like to clarify one thing please. In terms of physical security/access control. Would the departments who are in scope need to be physically isolated from the other departments who are out of scope?
Performing audits
1. How are the audits conducted?
Inventory of assets
I have a question about inventory of assets. The communication tool in our company is Slack. Should it be added in inventory list? The same question is for CRM. We are using Zoho CRM. Should we add it in our inventory list?
Defining scope
I am trying to scope out my ISMS. We have around 370 employees. 50 of them are remote workers. The business is an insurance brokers and the sales team rely on three brooking platforms to operate. I am unsure whether to include everything and the kind of business functions to include in the scope boundaries.