I bought some document from you're website but I still don't understand how to start with the risk analyse?
Performing audits
I was asked a question about the ISO 27001 the other day, and I wasn’t sure about the answer. So I thought to about checking with you.
Certification process
1. How best should we proceed with this certification? We are an NGO using data driven technology to improve public health delivery, public health emergency response and disease surveillance. If we opt for the toolkit approach what are the other associated costs like the reviewing of prepared documentations, etc. ?
Certificaciones de una proveedor cloud
quiero preguntar si es seguro manejar información en la nube por medio de un externo, que servicio me recomienda ?
Division of tasks
I am currently the only individual responsible for information security management, quality management, business continuity management and GDPR in an organisation with circa. 4-500 employees across UK and international offices?
Shared resources
In our Office we have one risk that I am not really sure what we can do to mitigate the risks, it is as following:
ISO 27001 implementation project
I want you to advise me on how i can prepare for an ISO S 27001project and especially how to tackle the gap assessment phase.
Applicability of controls
I have a question: I marked the whole section A.16 Information Security Incident Management as not applicable. You have made no comment on that. My question is this: Is that even allowed? Can it make any sense to not have an Incident Management system, when you strive to work in accordance with the PDCA cycle?
ISO 27005 Annexes
I am working on the development of InfoSec risk management framework. Can you please guide if we can use the Annex B, C, D (of ISO 27005:2011) in our own framework. Is there any compliance issue?
ISMS audit
I have a ISMS audit.Please guide me ho to proceed with documents and all process?