1 - In regards to the internal audit, it should be done right after training and awareness, correct?
Benefits of ISO 27001
Hi! Can you help me on what is the benefits of ISO 27001 to the organization. As of now i'm doing a proposal for are organization on what is the benefits of being ISO certified. We would like to convince then and courage then to pursue the certification for entire organization.
thanks
Performing risk assessment
So as I go through the risk treatment, I notice that most of the risks are less than a 3 therefore are accepted risks...However, that is because I already have a control in place or the likelihood is a 0...can I put "risk acceptance" in the risk treatment for "selection of options" and then put the control that is in place or that we will implement in "means of implementation"?
Root cause for identified non-conformities
Just wanted to know about what someone needs to provide as root cause for the identified non conformities And mainly corrective action details.
Standard in selection of partnership
Hello, I am performing research for a mortgage back office provider partnership opportunity. I would like to know if there are more than just the ISO 9001 for our line work or should we consider other certs?
Vendor Management Policy
I can't seem to find a Vendor Management Policy in the ISO 27001 Documentation Toolkit. Am I just missing it? Or, is there simply no such policy in the Toolkit?
BCP
hay algún ente (por ejemplo ISACA) que conste que X persona es apta para aplicar la metodología BCP de la ISO
¿Quien revisa y aprueba documentos?
quien debe Revisar y Aprobar los documentos??? En mi empresa existe un miembro del Consejo de Administración y mi persona como responsable de seguridad de la información.... Pero mi duda es esa Quien Revisa y Aprueba los documentos....??
Understanding ISO 27001
I felt that having MBA degree I may not be able to fully learn ISO 27001 especially the areas related to networking and penetration testing.
Protecting a network
Our office in Norway has a shared switch with another company. Only the other company has access to this switch and we see this as a potential risk that we want to minimize, but we don’t really know what the best solution is.