ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Audit checklist

    I am writing up a checklist for internal audit but got stuck wondering if we're supposed to audit the implementation of the standard or the implementation of our internal ruleset (policies/standards/instruction/etc)?
  • Management principles

    What are Management principles of an ISMS?
  • Auditing ISO 27001 and ISO 27018

    I work for a small company in Serbia, we are actually on our way of our ISMS implementation base on ISO 27001 and also on our way to be GDPR ready.
  • ISO 27001 competencies

    1- Hi, we have included all our employees in the scope for ISO 27001. Do we have to a competency matrix for all of them as per Clause 7.2 ? Or only for the ones with the Information Security role who have been assigned the responsibilty for ISMS ? Please clarify for who all the competency matrix is to be done ?
  • Opposition to implementation

    I would like to ask what opposition of management and stake holders might resist to the implementation of ISMS.
  • ISO 22301 questionnaires

    I need resources on ISO22301, kindly advise a typical questionnaire I can administer on a Bank client to extract the required information (project scope) regarding the audit and cer‎tification towards achieving ISO22301.
  • ISO 22301 implementation

    My organization is planning to implement ISO 22301 the following semester and we want to know what are the recommendations to implement this standard in a financial organization.
  • Use of cryptographic controls

    Can you please elaborate what kind of controls addressing under 10.1.1, as we as an organization just implemented the SSL certificate for securing our web interfaces acessed by external or remote users, in this regard can 10.1.1 caluse will be applicabe or not, in case it applicate so what kind the policy we have to draft at our side.
  • Toolkit content

    I have already purchased the toolkit and im currently running the internal audit. But while im going through the clauses and i want to know how and where is the 6.2 clause covered in the toolkit you provided us.
  • Critical processes, RTO and RPO

    How to Identify all business critical process and other dependent processes and hoe to calculate the RTO and RPO after BIA?