The company I am working for has decided to implement ISO 27001 for a division only, a Division building up an iPaaS. I have a question related to SOA.
Distance of recovery site
Is in ISO 22301 mentioned any specific kilometer distance between the fail-over data centers ? I Know that the selection of DC location/provider is a complex thing and many things are to be considered, but the people (mangers) are kind of discussing all over again a Number X or Y. If there would be some concrete number in ISO 22301 (or PCI-DSS or another ISO/??? market/industry relevant/authoritative document, the discussion could be over). Please advice.
BCMS presentation to top management
I would like to know you, if you have an awareness presentation customized for a top management, which illustrate the importance of the BCMS for the business, in order to ease their buy-in.
Toolkit content
1 - Document: Project plan
ISMS scope
Is it possible to share a copy of a completed ISMS scope document. This would help to understand the types of items that we should be thinking about. I understand it is business dependent but an example would be usefull
Difference between guideline and measure
With great interest I'm reading your articles about ISO 27001. One thing isn't clear to me: What is the difference between a guideline and a measure?
ISO 2700 implementation
1 - Can I implement ISO 27001 specific to one product of organization rather than the entire organization.
Budgeting ISO 27001 implementation
I am in the process of planning costs for consultancy and certification for ISO 27001 and SOC 2, I am wondering if this is something you can help me with.
Password security and ISO 27001
I was stunned by upper management today and did not have an answer for them. What is ISO 27001 policy on keeping system passwords, service passwords, and application passwords. This is at the administrator Level. Obviously writing them in a “little black book” is not the answer. Is there a recommended password vault. How does other handle this issue.
Risk Assessment on SDLC
This is another thought that I have on risk assessment.