ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • BIA questionnaire content

    The list of items you would have identified on page 115 { Becoming Resilient} to be included in the BIA Questionnaire...are all the items necessary?
  • Internal audit scope

    I am putting together a proposal for carrying out Internal audits for a client to ISO27001 Standards.  During an internal audit what areas should be covered, broadly speaking?
  • Categories of disruptive impact

    I noticed in your BIA template that the categories of disruptive impact were: 1 hr, 4hrs, 24,hrs, 2 days and 1 week. Can these categories change to say 0 mins, 15 minutes etc? What determines the categories? are they a set standard? or can it change with every BIA?
  • Surveillance and main audits

    1 - What's a surveillance audit?
  • ISO 27799 certification

    Our company will be launching products in the 'health data' space in the coming months, and (in GDPR parlance) will be both 'data processor' and 'data controller' depending on context. We're looking at ISO certification and would like to know whether ISO27799 is a good fit, and if so, what documentation to purchase from whom. There are so many toolkits and templates being offered, some must surely be better suited than others.
  • Information classification

    I am currently working with a Civil Marine construction company, that have a limited IT Infrastructure - mostly look after the ERP and few business applications. The company don't have a formal InfoSec section / role within Organization ... Here, I have few queries in this regard
  • Information classification

    I am currently working with a Civil Marine construction company, that have a limited IT Infrastructure - mostly look after the ERP and few business applications. The company don't have a formal InfoSec section / role within Organization ... Here, I have few queries in this regard
  • Templates for ISO 17025

    1 - Is there anyone else in your group that does Risk Management and Internal Audits for ISO 17025 “Calibration Certifications”? 2 - If not, will the templates in both your Risk and Internal Audit books provide enough guidance to apply elsewhere?
  • ISO 27001 and EU GDPR trainings

    I wanted a training on infosec and data protection and need some advice on them... which will be the best course for me ISO 27001 and EU GDPR?
  • ISO 27001 implementation

    I’m currently undertaking an ISO 27001:2013 project which is in the planning stage, I spoke to my boss about how I was going to implement this, stage by stage e.g. get project buy in and how to start scoping the ISMS etc.