I am an Information Security Officer in a retail industry company with hypermarkets and malls in XXXX. My company is in retail industry and our core business is providing and selling goods to our customers in these hypermarkets through Point of Sales terminals. We are also doing online E-Commerce through our website.
Information Transfer Procedure
I recently bought the 27001 documentation package from you and i found it really useful for myself and my organization.
ISO 27018
Our company provides cloud services as SaaS and uses Amazon infrastructure. I would like to ask you if ISO 27018 standard is applicable for us or not? How to determine that?
Risk assessment and SoA
I just have a question regarding the ISO 27001 standard which I am busy doing my course on. Does the standard define that the SOA must have risks listed in it, Is this a requirement in order to be certified and would the auditor want to see this?
Demostrar cumplimiento con ISO 22301
¿Qué debo hacer para demostrar que podemos cumplir con la ISO 22301?
Alta dirección
En nuestra empresa tenemos el recurso de una Gerencia que lleva o administra este rol y responsabilidad de Alta Dirección, quien si bien cumple con las actividades de AD, formalmente no es parte de la Alta Dirección a nivel de estructura, pues el nivel directivo o Alta Dirección está conformada por Directores, Vicepresidentes y el Presidente Ejecutivo, como indico esta Gerencia quien o desde donde se administra todo lo de la AD para el sistema, no cuenta con este nivel directivo. Por favor tu opinión y recomendaciones al respecto
Standards applicability
1 - I would like to know how these certifications work for Small Businesses / Sole traders? ( ISO 27001 / BS EN ISO 9001)
Audit results
Our Sales Department would like to share our ISO 27001 Internal and Certification Audit results with a customer of ours. We are still in the process of implementing the standard and have not had our first audit yet.
ISO 27001 and PCI DSS
I have just got an oppurtunity to work on PCI-DSS compliance project.
Toolkit content
I purchased the combined 27001 / 22301 templates. The business continuity plan is highly customized for the inclusion of a BCMS. Can you share a version of the business continuity plan document that may be scaled down to the 27001 requirements (without the assumption of a formalized BCMS)?