Wouldn't cloud/virtualized companies not be better suited for ISO 27017/18?
SoA information
I have a question about implementing SoA.
Competencies for ISO 27001
Is a CISP and other certifications a must have for implementer of ISO 27001?
Integrating multiple systems
We are implementing ISO 9001 and GDPR… but considering the business benefits to including ISO 27001. Implementing the first two are our business requirements. Do you have any suggestions to simplifying implementation of these multiple systems?
Control A.8.3.2 and commercial shredders
Because of control A.8.3.2 we want to buy a disk shredder. Does this shredder need some specific specifications (for example a specific security level?).
Certification of cloud based business
I am planning to go for 27k1 audit certification and GDPR DPO certification, just need to plan well my time. One question, is a very small “company” of Consultants, that only have resources in the cloud, able to be certified in 27K1?There are so many controls that don’t be applicable…
Risk management approach
Given that 27001 gives us freedom to choose the approach to RA, I've been doing some research of other standards that will help us do a more methodological approach. And I feel like I´m in the middle of the jungle right now.
Toolkit content
I have just noticed an Adviser Update relating to A13-01-1.2 Managing Network Services . However, in our Conformio package, I have only just notice A.13 refers to Communications Security with only one policy within - 01 Information Transfer Policy. Are we missing templates here. Can you kindly clarify this confusion on my end.
Metrics for Incident management
I would like to ask about the metrics for Incident management is it normal that at the service desk function not have SLAs for resolution in a company implementing ISO 9001 and 27001 ?
Certification costs
How much does it cost to get the final ISO certification and how does one find reputable companies?