I am subscribed on your learning platform and would like to know if there are links or referral documents for things to look out for when Auditing or reviewing the appropriateness of a data center.
Risk assessment questionnaire
Is there a questionnaire that i would give to each asset owner to answer, and with i would be able to know all the necessary info to do a proper risk assessment ? is that plausible? Because if i did an interview i would ask the owner to explain his business process and look at all the aspects where an attacker could attack, but if it was an excel sheet or an email questionnaire ? can that be done? Do you have any questionnaire examples?
Scope definition
In your blog describing problems with defining the scope in ISO 27001, there is a discussion about problems related to narrowing the scope to part of the organization, as opposed to the whole organization. It is not clear to me whether there would be problems in the situation where the whole organization is included, but only a specific type of information (e.g. only health information) is included in the scope. Do you predict problems with narrowing the scope based on the type of information?
Example of assets
I need assistance on likely information security assets in a manufacture company.
Segregation of responsibilities
Could you please explain this: to separate the operational responsibility for networks from the responsibility for sensitive applications and other systems
Risk treatment options
What about reducing and sharing the risks?¸
Risk assessment and PIA for EU GDPR
What about PIA for the EUGDPR - will the risk assessments for ISO be useful for this?
Measuring control effectiveness
Lets say that for example my company does not have any IDS system, how could i measure for example the probability of breach, and after implementing for example 2 factor authentication how would i measure the effectivness?
References on Procedure for Document Control in Toolkit
In the document control procedure section 2, why are there references to 22301 and BS 25999 which are business continuity related. surely they do not apply to iso 2700? So what reference documents should be referred to then please.
Supply chain risks
What about supply chain risks? What parameters are used for vulnerability measuring ?