SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • External documents to be controlled

    I have a question about the following document: Document Control Procedure. At paragraph 4 External Documents. What kind of documents are we talking about?
  • Data Protection Impact Analysis

    Nice product about BIA , but .... the first topic for discussion is DPIA in UE, like of BIA. Can you help in this part? It is very interesting from point of view on GDPR direction.
  • ISO 27001 and business continuity

    1 - My firm is more interested in the ISO22301 (BCP) model and framework. ISO27001 is more on DRP (IS) while ISO22301 is on crisis, disatster and business continuity on the holistic (business and systems) platform, am I right sir?
  • Threat Value VS Vulnerability Value

    Actually i need to understand how we can evaluate the threat value and the Vulnerability Value too and what is the relation between them? example : if i have a high threat value should the Vulnerability value to be high too or how can i calculate it
  • Risk assessment and information classification

    I would like to know if there is a specific Risk assessment done for Document classification. If you have a template or some reference document would be of great help
  • BCM presentation

    Kindly assist if you happen to have executive presentation on BCM. The presentation should include Crisis management and inform their responsibilities.
  • Standards and Frameworks Integration

    I am looking at integrating a bunch of standards and frameworks as one system; is this doable? specifically 20k; 22301; 27k; OHAS; COBIT 5; TOGAF, PMBOK, CMMI
  • Residual risk

    After conducting initial risk assessment and deciding on the pre-treatment scores, does a control have to be in place for a period of time before it can be measured in order to establish the post-treatment score and therefore the residual risk? Otherwise, what is the process for going from risk assessment to risk treatment in a single paperwork exercise? It seems quite arbitrary to look at a risk and score it pre and post treatment in the same risk assessment session; or is this the nature of
  • Toolkit content - business continuity

    en cual documento del paquete ISO 27001 puedo localizar los lineamientos de seguridad de la información en la continuidad de negocio? (ISO 27002:2013 Chapter 17)
  • Scope definition

    We are an IT delivery organization, consisting of several business units (most are projectbased, a few are delivering outsourcing services). These business units are legally private companies (in Dutch: B.V.)