I am currently working on the development of risk management framework (based on ISO 27005) for my company. I am little confused as why ISO 27005 only talks about the negative risks and why not about positive risks (opportunities)?
Mitigar el riesgo
¿cómo demostrar al auditor que el riesgo se mitiga si en realidad es cualitativo?
ISMS: Controls and measures
Hi,
can someone explain to me the difference between controls and measurements?
We have performed a risk assessment and we have identified risk and now some measures/measurements are ongoing (e.g. creating server hardening guide). Later we want to check if e.g. all servers have these hardening guide applied - is this the control or is it just audit?
ISO 27001 ¿Para personas y empresas?
The ISO 27001 certification is for people or companies? How can I convince my company to pay me an ISO 270001 certification? How long do I need to take a full workout? And what is the cost?
Implementation steps
When referring to implementation time, does that includes diagnosis, definition of a plan, implementation and certification? or its solely for certification?
Is there an explicit requirement to identify the key control activities in each process/procedure documentation? Is this something the auditors will look for?
Maintenance of records
How to maintain online ISMS records for a year surveillance and next ISMS cycle?
Internal audits records
I was on Your "ISO 27001: An overview of the ISMS implementation process" training. And I want to clarity one subject