ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • ISO 27001 controls validation

    We have to start an internal validation of controls for ISO implementation. We will start with validation of effectiveness of one control/domain that is claimed to have its implementation completed. To start with, we need to create a template to perform the internal audit/validation that we will use to capture findings and report on effectiveness.
  • Information security policy content

    I'm in the process of writing my Information Security Policy, as soon this is done, I will communicate with all my organization end users. My question is:
  • Analysis of external issues

    At the moment I am busy with an internship about ISO 27001. I want to do an external and an internal analysis in order to determine the scope of the ISMS. On your website I saw that the 7s model is a good way to describe the internal issues. What kind of method do you recommend for the external analysis?
  • Minor non conformity

    if a minor non conformity is found with the scope of the ISO 27001 certificate, can the company still market/advertise they hold the certificate?
  • Controls implementation

    We have reviewed the Checklist of Mandatory Documentation and clause ( Information Classification Policy) number A.8.2.1, A.8.2.2, and A.8.2.3 is under the list of Commonly Used Non-Mandatory Documents.
  • Risk Mitigation Options

    I bought the package, iso 27001 standard, but I can't find what paragraph it talks about the 4 mitigation options!?? I'm really wondering what paragraph it is. I just need a paragraph number.
  • ISO 27001 requirements

    What does ISO 27001 require when it comes to Physical Security? Building security..when it comes to fires, do they require a certain amount of extinguishers, etc. Cameras...etc..Locked doors...
  • BCM requirement in SLA or contract - Force majeure clause

    , the following continuity strategy will be applied:
  • BCP tests clause

    for BCP testing ? which clause expects this ?
  • Threats and small organizations

    I want to know what are the treats are mostly affected to the small organizations?