ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Implementing ISO 27001

    I'm struggling to know where to begin. There are so many documents - even the required only. Each has callouts to other documents. I'm not sure where to begin ... and when I am filling in the information, I feel like I'm making it up on the fly.
  • Frequency of performing internal audit of ISMS

    Could you please give some information concerning the ISO27001 requirement for frequency of performing internal audit of ISMS. Is there any clear requirement in the standard that organisation's internal audit must perform ISMS audit on annual basis?
  • BC policy and BC framework

    1 - what is the difference between a business continuity framework and a business continuity policy?
  • Documenting policies

    Senior management wants to put all policies into one document ("a manual") and therefore only sign/approve one document. Is this allowable for auditing purposes?
  • Access control policy: A.9.2.3

    Hello, My company bought the documentation of the Access Control Policy. At which part is control A.9.2.3 covered in this document? Yours sincerely, Tom van Ruitenbeek
  • External Auditor versus Lead Auditor

    I want to become an External Auditor, not a lead auditor.....Is there a difference when it comes to the qualifications? Can someone take the Internal Auditor course, get the Certification and then start doing ISO 27001 for my company at other sites?
  • Competence evidence

    What kind of evidence required for resource competence and attending training to address relevant cybersecurity risk?
  • Sample texts in templates

    I don't understand the part of "Managing records kept on the basis of this document" in document 00_Procedure_for_Document_and_Record_Control_Integrated_EN.docx
  • Delayed audit report

    I have post Internal audit problem with regards to incomplete and delayed reporting of internal audit carried out in April, 2017 the audit IQA-Q2 was closed out. However the report since April was never completed due to reshuffle and resignation of lead auditor and unavailability of the draft close out report.
  • Documents review criteria

    Could you please clarify, if we can indicate the revision of the documents (policies, procedures etc) "if necessary", or we should give the specific time frame, once a year, for example?