ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Toolkit content

    As for the Annual Internal Audit Program (I think that's one of the mandatory documents), I've seen the preview of the document. At the top it says "Internal audits according to ISO/IEC 27001 and ISO 22301/BS 25999-2 standards will be conducted in the following way". I was wondering why I have to do internal audits for ISO 22301/BS 25999-2 if I just want to be compliant with ISO 27001 for now?
  • ISO 27001 lead implementer and audit responsibility

    1. Is there any ISO 27K lead implementer certificate from ISO or just attending the course is enough?
  • Lead auditor certification

    From where I can get the certification to be lead auditor ISO 27001? Is it online exam?
  • BYOD policy content

    Please can you advise for ISO 27001 what is required if as a company we allow bring your own device (BYOD) – what does the standard require and what is best practice?
  • ISO 22301 and DRI practices

    "I will appreciate your kind clarification on my concern as stated below:
  • ISO 27001 implementation challenges

    1. Which are the first steps you would suggest to a company (financial institution) that is is only now starting to focus on Information Security ?
  • Risk assessment and risk register

    Are Risk Assessment and Risk Register different? I've made Risk Assessment template and found out some of risk register template that is more or less similar with risk assessment. Can this template be combine into one? or risk assessment template only is enough to comply the standard requirement?
  • Career on ISO 27001

    I am very much interested in becoming a Trainer/Auditor/Expert expert in ISO 27K. I'm an ISO 9001 Expert and had been auditing with SGS for the last 8 yrs. Could you please advise on the best pathway.
  • ISO 27001 clauses 6 and 8

    As per ISO 27001:2013, Clause 6.1.2 and 6.1.3 Speak about Information Security risk assessment and Treatment as well as Clause 8.2 and 8.3 explain about the same Security risk assessment and treatment. Can you please explain the requirement of each clause(6.1.2, 6.1.3, 8.2 and 8.3), whether they are the same or have a different requirement.
  • Identifying legal requirements

    1. law scope- LEGISLATION AND REGULATION RECORD- What is the accurate scope and commitment of Advent One in the legal context domain?