ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Records required in an IT project

    What information needs to be store for audits for IT project. My project having functions like register login logout, messaging
  • Toolkit list of documents

    1- I have two documents, both of which include a checklist of Mandatory Documents required by ISO 27001. However, there are some minor differences. Could you please confirm that the revised 2015 version 3.1 is the newest update and I should disregard the 2013 revision.
  • SoA content

    Does the SOA need to contain justification for inclusions, and whether they are implemented or not. I was under the impression only the reason for exclusion is required.
  • ISO 27001 Annex A checklist

    Is there a ISO 27001"2013 Appendix A Verification and Validation procedures that exists. We are going into stage 2 ISO Cert and for future assessments we will be doing need to have those procedures if they exist.
  • Operational planning and control documentation

    Is it a mandatory requirement to document 8.1 operational planning and control? My thoughts are around showing what controls and planning are in place rather than a 'manual' describing what we do.
  • ISO 27001 and PCI-DSS certifications

    I am working as a Information and Network Security consultant. I would like to do ISO 27000 module certification and PCI-DSS certification.
  • Checking information on significant residual risks

    1 - Explain how to check that information on significant residual risks is provided to the appropriate people?
  • Templates and ISO 27018 requirements

    We've purchased your ISO 27000 toolkit but I can't find any documents relating to Annex A.4.2 or A.18.1.1 which are referenced in your mapping of ISO 27000 with GDPR.
  • Lead Auditor and Lead Implementer Certifications

    I am looking to get a qualification in ISO 27001. Should I go for the PECB ISO 27001 LI or the IRCA ISO 27001 LA?
  • Internal audit

    As an implementer of ISO 27001 & the Information security manager writing the security policies at the company could I also perform internal audits myself for the ISMS too?