I am a student currently writing a coursework on Information security. I have tried to understand what ISO 27001 is but I still don't understand what is it and what it does. I was hoping you could help me understand what ISO 27001 is about and what it does.
BIA template
I need some example for BIA for system and process iso 22301
BCM and datacenters
We are building a new datacenter. Please let me know what could be my role as BCM manager for the company. Are there any benchmark or framework I should follow?
BCM awareness
Please advise if you design the BCM awareness material based on ISO22301 standard. Do you have videos for awareness?
ISO 27002 and application of control A.9.4.4
Regarding ISO 27002 and aplication of control A.9.4.4, in my opinion the control wants to have control over activity of SysAdmins when they use priviledged applications or tools. The auditee thinks that is enought with the Knoledge of the users who log in and log out. I think I am right, but I want others opinions in order to open the auditee's mind. What is your opinion ??
Internal team for penetration and vulnerability tests
Can a company have their own security team and perform the penetration testing and vulnerability tests for their infrastructure. is there a must to do that with a third party? or doing with the internal employees also okay? this has become a debate in our office now
GPDR training
What training do you provide to ensure the GPDR is understood, the difference between ISO 27001 and GPDR, and what the DPO needs to know?
ISO personal certifications and Content for employees
1. Is there an ISO certification like there is for COBIT Assessor?
Ensuring compliance of information security in projects
Considering this article: How to manage security in project management according to ISO 27001 A.6.1.5 , What about a Compliance Automation engine to make it all work ? And get ready for audit
Business continuity plans
Are there different types of types of business continuity plans?