I am working as a Information and Network Security consultant. I would like to do ISO 27000 module certification and PCI-DSS certification.
Checking information on significant residual risks
1 - Explain how to check that information on significant residual risks is provided to the appropriate people?
Templates and ISO 27018 requirements
We've purchased your ISO 27000 toolkit but I can't find any documents relating to Annex A.4.2 or A.18.1.1 which are referenced in your mapping of ISO 27000 with GDPR.
Lead Auditor and Lead Implementer Certifications
I am looking to get a qualification in ISO 27001. Should I go for the PECB ISO 27001 LI or the IRCA ISO 27001 LA?
Internal audit
As an implementer of ISO 27001 & the Information security manager writing the security policies at the company could I also perform internal audits myself for the ISMS too?
BCP Test
I have recently joined a company as Information Security Officer and I am curretly implementing ISO 27001. I am about to finish it in a months time. Before I was with them they have implemented BCP DR project and all the documents and implementation is done. Now its the time to test what has been implemented. I have a very less exp. in ISO 22301 and don't know where to start for the testing and drills? How to make the test plans, what to test first and what to test at the end. How to approach the stakeholder and how actually should I test the BCP DR project which has been implemented and the worst part is I was not part of it. I am just going through these documents and understanding what has been done by the consultant.
Communication procedure for ISO 22301
Many thanks for your valued information, and I would to ask you about draft SOP for communications according to ISO 22301:2012 clause 7.4 and 8.4.3
Equipment Maintenance in ISO 27001
Needs information about 11.2.4 Equipment Maintenance
Implementation steps
We prepare the mandatory documentation required by the standard, do documentation review whether policies are implemented and now we have risk assessment and risk treatment plan. My question is what is the next step after this
Information security in policy elaboration
Buenos días, que debo de tomar en cuenta para elaborar una política de becas y medias becas. En una escuela cristiana.