I find that the List of List of Legal, Regulatory, Contractual and Other Requirements is a mandatory document. I don't know how to fill this in. When it says "requirement" what is it asking for? Same for "document stipulating the req". Is there a tutorial for this one or a webinar? In what situation would this document be found applicable?
Cryptography and ISMS
I want ask you how can blockchain controlled by ISMS ?
Actually my company investing in blockchain technology, and i'm trying to know how can i cover that in my organization ISMS
iso27001 and iso20000
One of the topic I have seen in your website, the one related to integrated management system iso27001 and iso2000. I am wondering if this would work in reality, since IT and info sec would fall in different organization unit?
Internal Audit - Technical Knowledge
The Internal Auditor must have a high level of technical knowledge to audit the company respecting ISO 27001? what is the minimum knowledge needed...
Audit Plan
The Audit Plan is a document written per policy or department that will be audited or it is an overall document?
Internal Audit - Lack of Documentation
There is a Lack of Documentation in the company where I work, but they want that the audit team start with the internal audit, is this possible to do? or what can the audit team do while the documentation is not ready?
Address for certification
My organization has a total of 30+ employees and it is a kind-of virtual organization. We are registered but do not have a dedicated office location. We have hosted our environment in a cloud location managed by a CSP with proper segregation from other tenants. Our employees connect to platform through VPN across the globe. Our clients wants us to obtain ISO 27001 certification and we as an organization also want to establish an ISMS. Given this scenario, organization without a dedicated office location, can we go-ahead for ISO 27001 implementation and certification?