SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Competencies for ISO 27001 implementation and management

    1 - I've started your ISO 27001 course lectures. I have a question concerning the preparation process for becoming certified. The company I work for soon will start the process of certification which I will coordinate ( with the help of the consultant), since I have interest in the information security and I have some experience with ISO 27001 standard. My question is; do I have to have a certain certificate so I can handle this project and is the consultant necessary for the things I can manage myself (phase of first revision, determination of policies and necessary documents)?
  • ISO 27001 and EU GDPR

    We are trying to write a frame work for the organization based on the new GDPR(General Data Protection Regulation) passed in European Union. Since our company does business in the UK we will have to follow the GDPR guidelines. I wanted to write a frame work for the GDPR which speaks on the classification of data and how we protect data and further link it with the ISO 27001 standard documents which we already have.
  • ISO 27002 compatibility

    Does ISO 27002 compatible with IBM QRadar SIEM, for the out of the box reports and compliance?
  • Risk acceptance criteria

    If our risk acceptance criteria is only to treat the top 5 risks, is it acceptable to only have a risk treatment plan for our top 5 risks?
  • New ISO 27001, ISO 27002, ISO 27003

    1) I was wondering if your opinion on the updates with regard to ISO/IEC 27002 and 27003 (plus BS 27001:2017) would be covered in a future briefing?
  • ISMS scope

    I recently took on the CISO role at a software company that is interested in gaining 27001 certification for ONE of their products (which is hosted on xxxxx). Seems like we would have a limited scope, and all the controls would be relative to that software and its development?
  • Observer in a audit

    I have completed ISO 27001:2013 Lead auditor course recently.
  • ISMS scope definition

    I did have a question for you, with respect to the scope of the organisation. My existing plan/scope covers the whole of our single premises (and all departments). I was asked to look into the feasibility of only including support and installation for the scope. To be honest I could not see how this would be feasible, without putting nearly as much effort into this, which would be better spent doing the whole business.
  • ISMS implementation

    How can I establish the Information Security Management System (ISMS)?
  • IRCA auditor

    How to get the IRCA badge for being an IRCA certified Lead Auditor?