1 - We finished our ISO/IEC 27001:2013 audits and are waiting for our certificates. We are wondering how much effort compared to ISO/IEC 27001:2013 (we got your ISO 22301:2012 documentation) is required to implement ISO 22301 when an ISMS is already implemented.
I am looking at our suppliers and considering each one in terms of risk. I am aiming to define the level of risk as low, medium or high for each supplier.
Project plan content
Is it allowed to have the “Project Plan” include both ISMS and BCMS, or do those need to be separate documents/projects completely?
ISMS boundaries definition
We are working on determining and defining the boundaries for our ISMS. Is it necessary for us to cover all of our employees that work remotely in different states? These individuals do have access to our top level controls for information security.
Threat, risk and assessment examples
Do you have any examples of threat, risk, asset assessments for mostly information security...
Non financial impact rationale
How do I explain the rationale that the non financial impact is greater than a financial impact? For them the $ are important!
Access control policy template content
I have been working on completing the Access Control document using your template and I continue to have some confusion regarding the comments related to controls in Annex A. Perhaps it's just my inexperience, but an example of my confusion, and I've seen this across many of the comments, is section 3.7 related to regular review of access rights has a comment that suggests this section is not necessary if we do not need control A 9.2.5. Yet when I read that A.9.2.5 it is related to Security of equipment off premises:
ISMS statement
We currently have our ISMS statement on display and I was wondering if you could confirm whether this has to be checked or updated at certain frequencies i.e. yearly? If so does it have to be dated for the year too as well as signed?
Time scale for assessments
Hi, can the time scale assessments change ? So right now I used the time scales: