ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • BCP Test

    I have recently joined a company as Information Security Officer and I am curretly implementing ISO 27001. I am about to finish it in a months time. Before I was with them they have implemented BCP DR project and all the documents and implementation is done. Now its the time to test what has been implemented. I have a very less exp. in ISO 22301 and don't know where to start for the testing and drills? How to make the test plans, what to test first and what to test at the end. How to approach the stakeholder and how actually should I test the BCP DR project which has been implemented and the worst part is I was not part of it. I am just going through these documents and understanding what has been done by the consultant.
  • Communication procedure for ISO 22301

    Many thanks for your valued information, and I would to ask you about draft SOP for communications according to ISO 22301:2012 clause 7.4 and 8.4.3
  • Equipment Maintenance in ISO 27001

    Needs information about 11.2.4 Equipment Maintenance
  • Implementation steps

    We prepare the mandatory documentation required by the standard, do documentation review whether policies are implemented and now we have risk assessment and risk treatment plan. My question is what is the next step after this
  • Information security in policy elaboration

    Buenos días, que debo de tomar en cuenta para elaborar una política de becas y medias becas. En una escuela cristiana.
  • ISO management standards differences

    Buenas tardes, me gustaria saber cual es la diferencia entre las diferentes ISOS, por lo menos veo la 27001 y la 9001, cual es la diferencia entre estas? estoy buscando certificarme en estas normas y quiero entender un poco mas sobre ellas para pagar un curso introductorio. gracias
  • Application of controls A.10.1.1 and A.10.1.2

    If an organisation has DC issued by external party, and the organisation does NOT use an other encryption controls , will the control 10.1.1 and 10.1.2 be applicable ?? the organisation does not generate any digital certificate.
  • Remote Audit

    Can you say what proportion of auditing could be done through the system, remotely?
  • Information Security Governance In Health Services

    May I seek your opinions about key steps to take to implement IG Toolkit for a Healthcare organization in the UK?
  • Supplier security clauses

    Does the article https://advisera.com/27001academy/blog/2017/06/19/which-security-clauses-to-use-for-supplier-agreements/ hold all of the third party security clauses?