ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Positive and negative risks

    I am currently working on the development of risk management framework (based on ISO 27005) for my company. I am little confused as why ISO 27005 only talks about the negative risks and why not about positive risks (opportunities)?
  • Mitigar el riesgo

    ¿cómo demostrar al auditor que el riesgo se mitiga si en realidad es cualitativo?
  • ISMS: Controls and measures

    Hi, can someone explain to me the difference between controls and measurements? We have performed a risk assessment and we have identified risk and now some measures/measurements are ongoing (e.g. creating server hardening guide). Later we want to check if e.g. all servers have these hardening guide applied - is this the control or is it just audit?
  • ISO 27001 ¿Para personas y empresas?

    The ISO 27001 certification is for people or companies? How can I convince my company to pay me an ISO 270001 certification? How long do I need to take a full workout? And what is the cost?
  • Implementation steps

    When referring to implementation time, does that includes diagnosis, definition of a plan, implementation and certification? or its solely for certification?
  • ISO 27001 implementation

    We received this question:
  • Mandatory documents for ISO 27001

    For clause 4.2 of ISO27K, there is mandatory document about list of interested parties. In your article (https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/) there is no list of interested parties document as required. Can you explain about that?
  • Key control activities

    Is there an explicit requirement to identify the key control activities in each process/procedure documentation? Is this something the auditors will look for?
  • Maintenance of records

    How to maintain online ISMS records for a year surveillance and next ISMS cycle?
  • Internal audits records

    I was on Your "ISO 27001: An overview of the ISMS implementation process" training. And I want to clarity one subject