I recently took on the CISO role at a software company that is interested in gaining 27001 certification for ONE of their products (which is hosted on xxxxx). Seems like we would have a limited scope, and all the controls would be relative to that software and its development?
Observer in a audit
I have completed ISO 27001:2013 Lead auditor course recently.
ISMS scope definition
I did have a question for you, with respect to the scope of the organisation. My existing plan/scope covers the whole of our single premises (and all departments). I was asked to look into the feasibility of only including support and installation for the scope. To be honest I could not see how this would be feasible, without putting nearly as much effort into this, which would be better spent doing the whole business.
ISMS implementation
How can I establish the Information Security Management System (ISMS)?
IRCA auditor
How to get the IRCA badge for being an IRCA certified Lead Auditor?
Organizational context
Can you please elaborate different types of context as per ISO 27K prospective? Please provide relevant examples to understand the same.
Non Disclosure Agreement
I have another issue raised today when drafting out Non Disclosure Agreement. I hope you can help with this! What is the best practice duration of confidentiality agreement? if we say it is for particular number of years, for some highly sensitive information it may not be enough or if its to expire with the contract that's will not help also to protect the information.. I'm sure you will have a better idea on this and can help me come up with the best.
Cryptography verification
where is cryptography tested in ISO 27001?
BCP content
1 - Please on Wednesday webinar, I will appreciate if you would give time to discuss the content of a BCP plan:
ISO 27000 series quotations in academic work
Estou fazendo TCC sobre Política de Segurança da Informação no curso de Sistemas de Informação e gostaria de saber se posso citar textos das ISOs da família 27000 como citações diretas e indiretas no TCC, mesmo sem ter comprado de fato nenhuma norma.