Estou fazendo TCC sobre Política de Segurança da Informação no curso de Sistemas de Informação e gostaria de saber se posso citar textos das ISOs da família 27000 como citações diretas e indiretas no TCC, mesmo sem ter comprado de fato nenhuma norma.
ISO 27001 study material
I am currently taking your online course „internal auditor ISO27001.
SLA and ISO 27001
Is there a place in the ISO 27001 documentation for Customer Service Level Agreements? If so where do they fit in please and is there a template for them?
Security controls and SaaS
How many controls that are not applicable for organisation who has saas application? heard that 30 to 40% of cloud service provider controls are not applicable to cloud service customer curious to know what are those
Risk assessments
I have a few questions:
Surveillance audits
1 - What activities are involved during Surveillance audits held every year once ISO certification is issued?
Conformity with EU GDPR
For a company the conforming with ISO 27001 requests is enough for to be in law with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (General Data Protection Regulation) ?
ISO 27001 requirements for controls
I just want to check if ISO 27001 procedures require an immediate removal of IT staff's usernames when resignation? the IS audit manager at a local bank ? please note that, I mean the immediate removal before the notice period is done
Risk assessment
I have a question about Information security risk assessment – Risk analysis and evaluation [clause 6.1.2].
Information with different classification levels
I'm doing policy review for ISO 27k . I'd like to know, is it wrong to relate the policy statement with related SOP and both documents are not having the same classification