My company will start the certification process, but we do not know how to define the scope. Currently we are a Telecom company, and we provide Data Center solution (hosting, colocation and cloud) for our clients. We are in search of market repositioning, but we do not know which scope to limit to be able to stand out to us.
Planning information security continuity
I am working through the ISO templates we purchased. In regards to this control (Planning information security continuity), I don’t understand what it means. Do you have any examples or more guidance on what we are to do here?
Maintenance of records
We received this question:
Recorded Sessions from CCTVs, how long are they required to be kept for? How far back are they to be backed up for ISO 27001, ISO 22301 and PCI all respectively please?
Information security resources
I am from network security background, and willing move on Info Sec.
Could you please suggest me some materials or websites where to start from.
ISO 27001 versions
I am preparing for the interview and one questions that comes in my mind.
Knowledge and certifications for the Information security Officer
Just wanted to know what kind of knowledge and certifications do I need be able to fulfill a role as Information security Officer?
Audit and certification
Who will do the audit and certification? Once we prepare the documentation and implement all that is needed, which organization will do the audits and the random audits during the 3 years? Will this be an outside appointed body or some individual qualified 27001 auditor who can do the audit?
Internal audit results
1- Hope all is well with, we conduct an ISO audit as a part of Internal audit plan. What happens if we have repeat minor nonconformity findings (two of them).
Information security resources
I was dealing with information security topics in my previous work, a few years ago, and after that, my journey changed a bit and went to the other side.
Qualifications to perform ISMS internal audits
I want to understand the qualifications that are recommended to perform ISMS audits internally. I firm believe that certification give a person accreditation to perform such audits.