ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Controls required for ISO 27001 certification

    Currently elements of specific requirements for 27001 are missing (Asset Management/Active Directory/User Access/'Screening of staff at recruitment stage/Procurement process which is currently being reorganised. I have advised that these elements need to be in place before we even consider ISO 27001 certification..Am I correct in saying this?
  • Implementar ISO 22301 sin ISO 27001

    Pregunta: es posible implementar la ISO 22301 sin la iso 27001? Respuesta: Completamente, aunque si implementas ISO 27001, la implementación de ISO 22301 puede ser muy sencilla, porque ambos estándares tienen muchos puntos en común. Este webinar te puede resultar interesante: https://advisera.com/27001academy/es/webinar/iso-27001-iso-22301-why-is-it-better-to-implement-them-together-free-webinar/
  • Interested parties

    A quick question on interested parties in ISO 27001. How do employee families count as interested parties/how are they considered a stake holder?
  • Firewall use requirements

    We currently using the Opensource Firewall in our organization. Is that mandatory to use the Licensed Firewall for ISO 27001? Or the Opensource Firewall can be used and control?
  • Risk assessment on IaaS

    I have a query. I want to do risk assessment based on ISO 27001 of one of my business process build on IaaS (Infrastructure as a Service) from AWS. So the query is will the risk management approach differs while working in the cloud.
  • Implementing BCM

    How a fixed line telco operator can implement all stages of BCM as most of the expertise available if for IT services?
  • BIA and business strategy

    How to incorporate BIA into company's digital transformation strategy?
  • Weak signal detection and ISO 31000

    I do BIA at clients without ISO. Though I will follow this week an ISO 31000 course and exam. How to include weak signal detection (foresight)? How to integrate - link with ISO 31000?
  • Activity Recovery Strategy and Plan

    I am for the first time using your two templates that deal with these two areas of developing the plans. Both of these deal with each and every activity individually. It seems a lot of documents a lot of detail and I am wandering what the reason may be. With the kind of solutions around today where virtualization, replication, warm sites etc. recovery of ICT is almost a matter of flicking a switch. I am busy with a very large client with a complex environment and can see the need. I also recently did a small client with a simple environment where ICT is replicated at the alternate site, switched over and users are able to work, we have Simplicity in between. The need for individual focus in this way was not necessary so strategy and plan was one document. This could apply equally to a large environment if they choose such a solution.
  • Risk value calculation

    When completing the risk assessment table, should the risk value (specifically the Likelihood component) be decided on before or after considering any existing controls?