We are implementing ISO 9001 and GDPR… but considering the business benefits to including ISO 27001. Implementing the first two are our business requirements. Do you have any suggestions to simplifying implementation of these multiple systems?
Control A.8.3.2 and commercial shredders
Because of control A.8.3.2 we want to buy a disk shredder. Does this shredder need some specific specifications (for example a specific security level?).
Certification of cloud based business
I am planning to go for 27k1 audit certification and GDPR DPO certification, just need to plan well my time. One question, is a very small “company” of Consultants, that only have resources in the cloud, able to be certified in 27K1?There are so many controls that don’t be applicable…
Risk management approach
Given that 27001 gives us freedom to choose the approach to RA, I've been doing some research of other standards that will help us do a more methodological approach. And I feel like I´m in the middle of the jungle right now.
Toolkit content
I have just noticed an Adviser Update relating to A13-01-1.2 Managing Network Services . However, in our Conformio package, I have only just notice A.13 refers to Communications Security with only one policy within - 01 Information Transfer Policy. Are we missing templates here. Can you kindly clarify this confusion on my end.
Metrics for Incident management
I would like to ask about the metrics for Incident management is it normal that at the service desk function not have SLAs for resolution in a company implementing ISO 9001 and 27001 ?
Certification costs
How much does it cost to get the final ISO certification and how does one find reputable companies?
Building Business Continuity strategy
We built our DR plan for IT service and we would like to know the road map of building Business Continuity strategy and plan for the whole organization?
Career on information security
I am learning ISO 27001 documentation structure and working on the documentations as well. Can you help me to understand and provide me a better way to enhance my career in this field ?
Toolkit content
I quickly browsed through the list of docs and noticed that while it covers the Annexure A (A5 - A18) controls very well, there is no documentation to address the ISMS part. i.e clause 4 to Clause 10 of the 2013 standard. Could you please comment on that? Did I miss anything?