ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • ISO 27005 Annexes

    I am working on the development of InfoSec risk management framework. Can you please guide if we can use the Annex B, C, D (of ISO 27005:2011) in our own framework. Is there any compliance issue?
  • ISMS audit

    I have a ISMS audit.Please guide me ho to proceed with documents and all process?
  • ISO 22301 implementation

    1 - We finished our ISO/IEC 27001:2013 audits and are waiting for our certificates. We are wondering how much effort compared to ISO/IEC 27001:2013 (we got your ISO 22301:2012 documentation) is required to implement ISO 22301 when an ISMS is already implemented.
  • Lead implementer exam

    I attended the Foundation Course and I also bought your book "https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/#reviews"
  • Performing risk assessment

    I am looking at our suppliers and considering each one in terms of risk. I am aiming to define the level of risk as low, medium or high for each supplier.
  • Project plan content

    Is it allowed to have the “Project Plan” include both ISMS and BCMS, or do those need to be separate documents/projects completely?
  • ISMS boundaries definition

    We are working on determining and defining the boundaries for our ISMS. Is it necessary for us to cover all of our employees that work remotely in different states? These individuals do have access to our top level controls for information security.
  • Threat, risk and assessment examples

    Do you have any examples of threat, risk, asset assessments for mostly information security...
  • Non financial impact rationale

    How do I explain the rationale that the non financial impact is greater than a financial impact? For them the $ are important!
  • Access control policy template content

    I have been working on completing the Access Control document using your template and I continue to have some confusion regarding the comments related to controls in Annex A. Perhaps it's just my inexperience, but an example of my confusion, and I've seen this across many of the comments, is section 3.7 related to regular review of access rights has a comment that suggests this section is not necessary if we do not need control A 9.2.5. Yet when I read that A.9.2.5 it is related to Security of equipment off premises: