What is your opinion on FMEA risk assessment methodology? What is the simplest and easiest (acceptable) risk assessment methodology for ISMS?
Compliance questionnaire
Estou fazendo um trabalho acadêmico (Artigo) sobre segurança da informação no qual eu tenho que elaborar um questionário com o objetivo de analisar a aderência da segurança da informação adotadas nas empresas com a norma ISO 27002.
ISO 27001 standard course
I am going through course for 27001 standard and I noticed it's not updated to a new format of the standard. I believe it's 14 clauses now and 111 controls in Annex A.
Audit and ISO 22301
1 - Kindly assist me with the audit program for ISO 22301 as well as test plans.
SOA preparation
When am I supposed to prepare the SOA? I am performing the RA now. Please advise
Idioma de la documentación del SGSI
los documentos deben ser creados en el lenguaje del país original y si la divulgación va mas alla de este país debe hacerse en el lenguaje oficial internacional, Ingles.
Application of control A.18.1.1
I am having some trouble with A.18.1.1. Do I need explicitly identify every applicable requirement for the every law and standard applicable to our company such as all accounting, human resource (Federal, State and local) or it should be towards our services that we provide?
Organizational unit responsible for ISO standards
When a new department is formed to establish and ensure certifications for ISO27001, ISO22301, ISO20000, what name should that department be called? Scenario: This new department does not consist of any Subject Matter Expert on any of these areas: ISMS, BCMS, ITSM as these experts will be in other departments which are more specific to their expertise, example Application Development Department, Infrastructure & Security Department etc. Meaning this new department will only be manned by a few personnel who will lead the implementation of ISO 27001, ISO 22301, ISO 20000, taking the role as facilitators to the SME in ensuring it complies to the Standards. An Audit Team will also be in this Department. So may I have your suggestion what is the best name to label this new department. Are these names applicable/ suitable? Suggestions: 1) ISO Compliance Department 2) Quality Management Department
Risk assessment
My question regarding risk assessment is how to conduct the table tools of it.