ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Surveillance and main audits

    1 - What's a surveillance audit?
  • ISO 27799 certification

    Our company will be launching products in the 'health data' space in the coming months, and (in GDPR parlance) will be both 'data processor' and 'data controller' depending on context. We're looking at ISO certification and would like to know whether ISO27799 is a good fit, and if so, what documentation to purchase from whom. There are so many toolkits and templates being offered, some must surely be better suited than others.
  • Information classification

    I am currently working with a Civil Marine construction company, that have a limited IT Infrastructure - mostly look after the ERP and few business applications. The company don't have a formal InfoSec section / role within Organization ... Here, I have few queries in this regard
  • Information classification

    I am currently working with a Civil Marine construction company, that have a limited IT Infrastructure - mostly look after the ERP and few business applications. The company don't have a formal InfoSec section / role within Organization ... Here, I have few queries in this regard
  • Templates for ISO 17025

    1 - Is there anyone else in your group that does Risk Management and Internal Audits for ISO 17025 “Calibration Certifications”? 2 - If not, will the templates in both your Risk and Internal Audit books provide enough guidance to apply elsewhere?
  • ISO 27001 and EU GDPR trainings

    I wanted a training on infosec and data protection and need some advice on them... which will be the best course for me ISO 27001 and EU GDPR?
  • ISO 27001 implementation

    I’m currently undertaking an ISO 27001:2013 project which is in the planning stage, I spoke to my boss about how I was going to implement this, stage by stage e.g. get project buy in and how to start scoping the ISMS etc.
  • Cloud toolkit

    Considering the answer:
  • Risk Register vs Incident Log

    Are the risk register and incident log mutually exclusive or complementary documents? Are they both strictly necessary?
  • ¿Apéndices en la ISO 22301?

    Cuando en la norma ISO 22301 hablan apéndices a que se están refiriendo?