In the mandatory ISO 27001 documents published on your site, you say it is required to have the following below:
Definition of security roles and responsibilities
Ok, so there is a mandatory document if applicable, which is called the definition of security roles and responsibilities (clause A.7.1.2 and A.13.2.4). However, I cannot find it in the toolkit. Is it under a different name? cause I just looked through the documents in conformio and didn't see it
SoA update
Can we update the SOA document once it's already been shared with the auditors?
Examples for the risk assessment and risk treatment
Do you have some examples for the risk assessment and risk treatment?
Business Continuity in SLAs
How can we deal with force majeure clause excuses vendors from disaster recovery / BCP responsibilities.
ISO 27001 controls validation
We have to start an internal validation of controls for ISO implementation. We will start with validation of effectiveness of one control/domain that is claimed to have its implementation completed. To start with, we need to create a template to perform the internal audit/validation that we will use to capture findings and report on effectiveness.
Information security policy content
I'm in the process of writing my Information Security Policy, as soon this is done, I will communicate with all my organization end users. My question is:
Analysis of external issues
At the moment I am busy with an internship about ISO 27001. I want to do an external and an internal analysis in order to determine the scope of the ISMS. On your website I saw that the 7s model is a good way to describe the internal issues. What kind of method do you recommend for the external analysis?
Minor non conformity
if a minor non conformity is found with the scope of the ISO 27001 certificate, can the company still market/advertise they hold the certificate?
Controls implementation
We have reviewed the Checklist of Mandatory Documentation and clause ( Information Classification Policy) number A.8.2.1, A.8.2.2, and A.8.2.3 is under the list of Commonly Used Non-Mandatory Documents.