We just passed the ISO 9001 and 14001 audit. To be honest, we have 2 critical non-conformities, but this is just plain paperwork to lift it to non critical.
Risk assessment approach
Which is good approach for risk assessment
Positive and negative risks
I am currently working on the development of risk management framework (based on ISO 27005) for my company. I am little confused as why ISO 27005 only talks about the negative risks and why not about positive risks (opportunities)?
Mitigar el riesgo
¿cómo demostrar al auditor que el riesgo se mitiga si en realidad es cualitativo?
ISMS: Controls and measures
Hi,
can someone explain to me the difference between controls and measurements?
We have performed a risk assessment and we have identified risk and now some measures/measurements are ongoing (e.g. creating server hardening guide). Later we want to check if e.g. all servers have these hardening guide applied - is this the control or is it just audit?
ISO 27001 ¿Para personas y empresas?
The ISO 27001 certification is for people or companies? How can I convince my company to pay me an ISO 270001 certification? How long do I need to take a full workout? And what is the cost?
Implementation steps
When referring to implementation time, does that includes diagnosis, definition of a plan, implementation and certification? or its solely for certification?
Is there an explicit requirement to identify the key control activities in each process/procedure documentation? Is this something the auditors will look for?