ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Material for information protection

    I need to find a course or material to assist we and guide me in doing the following regarding data classification security.
  • Difference between sites and Certificates in ISO SURVEY

    I'm reading the survey publish on the ISO page, https://www.iso.org/the-iso-survey.html, but i'm confused because they are mentioning two different things Certificates and another column for Sites. What this means? they are different types?
  • Implementing ISO 22301 with support of ISO 27001

    I have bought from you the ISO_27001_ISO_22301_Premium_Documentation_Toolkit_EN back around May 2015 I believe; I have successfully been certified against ISO 27001:2013 by BSI, and now in process of implementing the ISO 22301:2012, to get certified around July 2017.
  • Risk assessment and BIA

    What would be the best practice for inclusion of ISMS risk in the BIA analysis, or in the questionnaire? My colleague, ISMS manager thinks I should add to BIA questionnaire fields with URLs applications that are used, so we are interested in what is "best practice" for this purpose?
  • Implementing a Business Impact Analysis according ISO 22301

    Seguramente una vez un webinar colmado de profesionalismo y sabiduría.
  • Auditor's opinion

    Hypothetically speaking how do you think an ISO 27001 auditor would view the following situation: a firm that is very paper dependent, through the risk assessment process has identified risks to the papers, the impact of which could be very high not only financially but to the reputation as well. Following the risk assessment that firm then chose to accept the risks of loss of confidentiality and availability of those documents and not implement a clear desk policy and provide some additional storage in order for the organisation to securely lock the documents away at night.
  • Convergence of ISO 27001 and ISO 22301

    We have a project to determine the feasibility in convergence of ISO 27001 and ISO 22301 by creating a single policy for both standards. Alternatively we would like to create an overarching policy which would describe our process for both standards. Can you advise how this can be achieved and whether you have a toolkit which can assist with this goal.
  • HIPAA and ISO 27001

    If an organization is already compliant to HIPAA, and is considering ISO 27001 compliance, how can they leverage their HIPAA compliance to speed up ISO 27001 compliance (e.g. is there a mapping available)?
  • BIA and risk assessment

    1 - The BIA includes a risk assessment?

    2 - Should The BIA questionnaire be different for every business unit into the company?
  • ISO 27001 clause 7

    I did not find any article on the site advisera.com/27001academy on the clauses 7. Support, 7.1 Resources and 7.2 Competence. I have difficulty interpreting these clauses. Can you help me?