I just have a question regarding the ISO 27001 standard which I am busy doing my course on. Does the standard define that the SOA must have risks listed in it, Is this a requirement in order to be certified and would the auditor want to see this?
Demostrar cumplimiento con ISO 22301
¿Qué debo hacer para demostrar que podemos cumplir con la ISO 22301?
Alta dirección
En nuestra empresa tenemos el recurso de una Gerencia que lleva o administra este rol y responsabilidad de Alta Dirección, quien si bien cumple con las actividades de AD, formalmente no es parte de la Alta Dirección a nivel de estructura, pues el nivel directivo o Alta Dirección está conformada por Directores, Vicepresidentes y el Presidente Ejecutivo, como indico esta Gerencia quien o desde donde se administra todo lo de la AD para el sistema, no cuenta con este nivel directivo. Por favor tu opinión y recomendaciones al respecto
Standards applicability
1 - I would like to know how these certifications work for Small Businesses / Sole traders? ( ISO 27001 / BS EN ISO 9001)
Audit results
Our Sales Department would like to share our ISO 27001 Internal and Certification Audit results with a customer of ours. We are still in the process of implementing the standard and have not had our first audit yet.
ISO 27001 and PCI DSS
I have just got an oppurtunity to work on PCI-DSS compliance project.
Toolkit content
I purchased the combined 27001 / 22301 templates. The business continuity plan is highly customized for the inclusion of a BCMS. Can you share a version of the business continuity plan document that may be scaled down to the 27001 requirements (without the assumption of a formalized BCMS)?
Controls identification
Is this mandatory to include control numbers in Risk Assessment as a part of Implementation of ISO 27001?
Control A14.1.1
I am working on this control and it refers to the Security Requirement Specification – I can only find the template Appendix_Specification_of_Information_System_Requirements_EN.docx.
Documentation examples
I wonder if you have some exemple of complete document regarding to SGSI. I am more than happy if you could share it with me.