I am currently taking your online course „internal auditor ISO27001.
SLA and ISO 27001
Is there a place in the ISO 27001 documentation for Customer Service Level Agreements? If so where do they fit in please and is there a template for them?
Security controls and SaaS
How many controls that are not applicable for organisation who has saas application? heard that 30 to 40% of cloud service provider controls are not applicable to cloud service customer curious to know what are those
Risk assessments
I have a few questions:
Surveillance audits
1 - What activities are involved during Surveillance audits held every year once ISO certification is issued?
Conformity with EU GDPR
For a company the conforming with ISO 27001 requests is enough for to be in law with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (General Data Protection Regulation) ?
ISO 27001 requirements for controls
I just want to check if ISO 27001 procedures require an immediate removal of IT staff's usernames when resignation? the IS audit manager at a local bank ? please note that, I mean the immediate removal before the notice period is done
Risk assessment
I have a question about Information security risk assessment – Risk analysis and evaluation [clause 6.1.2].
Information with different classification levels
I'm doing policy review for ISO 27k . I'd like to know, is it wrong to relate the policy statement with related SOP and both documents are not having the same classification
Information with different classifications
I'm doing policy review for ISO 27k . I'd like to know, is it wrong to relate the policy statement with related SOP and both documents are not having the same classification