ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Residual Risk

    After conducting initial risk assessment and deciding on the pre-treatment scores, does a control have to be in place for a period of time before it can be measured in order to establish the post-treatment score and therefore the residual risk? Otherwise, what is the process for going from risk assessment to risk treatment in a single paperwork exercise? It seems quite arbitrary to look at a risk and score it pre and post treatment in the same risk assessment session; or is this the nature of
  • Acceptable Risk Document

    What can be the contents of an acceptable risk document (ARD) in ISO27001? I am talking about a typical IT Organisation required to be maintained by information security team .
  • Incident Response Plan and Recovery Plan

    I have one question only in the Incident response plan (IRP) template. Our approach is BCP per department and one coordinator each. My understanding in the IRP is a separate plan to be activated during emergency or incident like if your critical department activities are threatened by one of your identified threats. This IRP also is different from Recovery Plan as this will be activated during the actual disruption or disaster. Is my understanding correct?
  • ISO 27001 and Data privacy protection regulations

    ISO 27001 and DSGV - Data privacy protection regulations - in Germany and EUROPE - checklist
  • ISO 27001 software

    Is there a software that automates ISO 27001?
  • Information Security Risk Metrics

    What will be the Information Security Risk Metrics or KRI (key risk indicators )?
  • Filling documentation

    We're a gaming software company who runs XXXX. Last month we've acquired UKGC license, and we have to do security audit with ISO 27001.
  • Conflicting management systems

    One of the challenges I have seen in large organizations is when different stakeholder sponsor implementation of ISO22301 and ISO27001 and come up with different versions of policies for the same concept. Also the entire process becomes extremely cumbersome for employees that need to provide feedback multiple times for essentially the same concepts.
  • ISO 27001 and PCI DSS

    if we are a ISO 27000 certified Company, and we are now, as a travel agency, also required by IATA to be PCI DSS compliant, does the ISO 27000 certification EQUAL or contribute to the PCI compliance? Simply put - if we are 27000 compliant - do we still need to be PCI compliant AS WELL or are we automatically PCI compliant when we are ISO 27000 compliant?