Currently I am a Hosted system engineer at XXXXX. My Job description is below:
Maturity in ISO evaluation
Can you define for me the "maturity" in ISO evaluation?
Incorporating ISO clauses in an internal audit
I'm expected to conduct an internal audit for one of our policies within our isms.. and i wasn't sure how i'm suppose to incorporate iso clauses? Am I expected to check for those clauses when i'm conducting an internal audit. Reading policies and the interviews etc i understand it's how to incorporate or make sure it all links to the standard. but i'm not interested in signing up for anything really just need to figure out the above.
Do we need to implement all the controls from SoA for the certification?
Do we need to implement all the controls from Statement of Applicability for the certification? Any idea regarding the percentage of status of the controls in the SoA that can be “planned”, “partially” or “implemented"?
How is the ISO 27001 Internal Auditor Course structured
What I needed to see was material control requirements
ISO 27001 Gap Analysis Tool
Does your gap analysis tool cover Annex A as well or only the mandatory documents?
Information as an asset
General question regarding asset. - Should we treat lets say customer information as an asset or the database storing the customer information as the asset?
Vulnerabilities identification
I would also like to know when talking about the vulnerabilities that I shall be considering for the risk assessment for my system/organisation, should that be what I got from Vulnerability Assessment(VA) using tools like Nessus or find vulnerabilities by manual efforts & if not then what should the perfect source be?
Standard for Disaster Recovery
Hello , i have one more question about Iso .
ISO 27001 Annex A
Is Annex A provided with the Advisera templates? Your colleague said this on the Expert Advice Community: