I have a question: I marked the whole section A.16 Information Security Incident Management as not applicable. You have made no comment on that. My question is this: Is that even allowed? Can it make any sense to not have an Incident Management system, when you strive to work in accordance with the PDCA cycle?
ISO 27005 Annexes
I am working on the development of InfoSec risk management framework. Can you please guide if we can use the Annex B, C, D (of ISO 27005:2011) in our own framework. Is there any compliance issue?
ISMS audit
I have a ISMS audit.Please guide me ho to proceed with documents and all process?
ISO 22301 implementation
1 - We finished our ISO/IEC 27001:2013 audits and are waiting for our certificates. We are wondering how much effort compared to ISO/IEC 27001:2013 (we got your ISO 22301:2012 documentation) is required to implement ISO 22301 when an ISMS is already implemented.
I am looking at our suppliers and considering each one in terms of risk. I am aiming to define the level of risk as low, medium or high for each supplier.
Project plan content
Is it allowed to have the “Project Plan” include both ISMS and BCMS, or do those need to be separate documents/projects completely?
ISMS boundaries definition
We are working on determining and defining the boundaries for our ISMS. Is it necessary for us to cover all of our employees that work remotely in different states? These individuals do have access to our top level controls for information security.
Threat, risk and assessment examples
Do you have any examples of threat, risk, asset assessments for mostly information security...
Non financial impact rationale
How do I explain the rationale that the non financial impact is greater than a financial impact? For them the $ are important!