ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Project plan content

    Is it allowed to have the “Project Plan” include both ISMS and BCMS, or do those need to be separate documents/projects completely?
  • ISMS boundaries definition

    We are working on determining and defining the boundaries for our ISMS. Is it necessary for us to cover all of our employees that work remotely in different states? These individuals do have access to our top level controls for information security.
  • Threat, risk and assessment examples

    Do you have any examples of threat, risk, asset assessments for mostly information security...
  • Non financial impact rationale

    How do I explain the rationale that the non financial impact is greater than a financial impact? For them the $ are important!
  • Access control policy template content

    I have been working on completing the Access Control document using your template and I continue to have some confusion regarding the comments related to controls in Annex A. Perhaps it's just my inexperience, but an example of my confusion, and I've seen this across many of the comments, is section 3.7 related to regular review of access rights has a comment that suggests this section is not necessary if we do not need control A 9.2.5. Yet when I read that A.9.2.5 it is related to Security of equipment off premises:
  • ISMS statement

    We currently have our ISMS statement on display and I was wondering if you could confirm whether this has to be checked or updated at certain frequencies i.e. yearly? If so does it have to be dated for the year too as well as signed?
  • Time scale for assessments

    Hi, can the time scale assessments change ? So right now I used the time scales:
  • BIA questionnaire content

    The list of items you would have identified on page 115 { Becoming Resilient} to be included in the BIA Questionnaire...are all the items necessary?
  • Internal audit scope

    I am putting together a proposal for carrying out Internal audits for a client to ISO27001 Standards.  During an internal audit what areas should be covered, broadly speaking?
  • Categories of disruptive impact

    I noticed in your BIA template that the categories of disruptive impact were: 1 hr, 4hrs, 24,hrs, 2 days and 1 week. Can these categories change to say 0 mins, 15 minutes etc? What determines the categories? are they a set standard? or can it change with every BIA?