Thanks for the previous feedback. I have another question. It is regarding the risk assessment. This is the first risk assessment they are performing since beginning their journey towards ISO 27001 certification. We are keeping the risk assessment at a higher level at this time.
Nivel de confidencialidad
tiene un ejemplo de como poner o que opciones podrían ser lo que va en la parte donde dice nivel de confidencialidad.
Identification of applicable controls
I need to understand what are the basic controls that need to be available for a small company of 20-30 employees. I am going to audit for small business and need idea what controls should be looked for from ISO 27001. The company is planning to get certified on ISO 27001.
Surveillance audit
Hello, at 2016, we accredited for ISO 27001:2013 ISMS without major non-conformity, surveillance audit should be established Dec 2017 while this audit not completed till now due to we are moving from one a new building on the same city.
ISO 9001 or ISO 13485
I was looking into other types of ISO certifications. The company I would like to get certified is XXXX. The website explains what the company is all about. I am currently implementing ISO 27001 for another company using your templates. My question is, which ISO standard do you think XXXX would benefit most from? I am thinking ISO 9001. What do you think? Would ISO 13485 be applicable?
Handling non-conformities
I have a few major and minor non conformances from my certification audit which stems from outsourced services.Do o need to prepare a root cause analysis for outsourced services?
Disaster Recovery Plan template
I looked at it but didn’t really see how to utilize it. You have only one RTO under general information. I would think you would have a more complex table for each application. I don’t really see a way to include that in your template.
¿ISO 27001 para seguridad y salud laboral?
¿esta norma puede ser utilizada para crear un plan de medidas preventivas en cuanto a seguridad y salud laboral, junto con la norma iso 10005 que me permite tener la estructura para crear el plan?
ISO 27001 implementation
1 - What are the requirements for implementing ISO27001? Who can implement it and what type of experience is required?
Risk management
1- They ask for us to consider assets. Would a non-tangible assets such as intellectual property be considered an asset for ISO 27001.