ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • ISO 27001 Presentation to Top Management

    Do you have presentation for top management to illustrate the benefits and importance of ISMS to organization ?
  • CISM and ISACA

    I would like to inquire if you have something specific for CISM -ISACA? e.g materials , Q&A samples….etc. thanks much indeed and really appreciated
  • Integrating ISO management systems

    how integrate iso27001 with other system , 9001:2015,14001,18001.
  • Methodology for calculating risk

    I have purchased the ISO 27001/ISO 22301 Risk Assessment Toolkit yesterday. I am keen to know regarding the calculations related to the RISK assessments especially the methodology which is being used. Any additional information related to this would be useful.
  • Information security in project management

    I just wondered whether you have a template for control 6.1.5 (Information Security in Project Management)? I am struggling with how to write it. Kindly provide me with some indicators in the absence of a template on what to include. I am assuming that it will impact the entire project management cycle. The issue is that we have there different entry points for new projects and ten there are some rare occasions where some projects are run by branch offices without an approval from a central body. How would you recommend going about writing the control in this case?
  • Organizational context and Risk Assessment Report

    1 - Do I need to prepare some reports when risk assessment and risk treatment are done? I am asking because in your template “Risk assessment and risk treatment report” there is one sentence under “Time period” there is a sentence saying:"Risk assessment was implemented in the period from xxxxxxxxxx to xxxxxxxxx. Risk treatment was implemented from xxxxxxxxx to xxxxxxx. Final reports were prepared during xxxxxxxx to xxxxxxx."
  • Controls applicable to suppliers

    I want to know the list of controls applicable to a third party in case you outsource a service to him?
  • Procedure for management of NC and CA

    Can ISMS non-conformities be addressed by this procedure: https://advisera.com/14001academy/documentation/procedure-for-the-management-of-nonconformities-corrective-and-preventive-actions/
  • Expanding ISMS scope

    A client currently certified for their organisation in ISO 9001, and also certified ISO 27001:2013 in one of their departments. My question is how can they move forward to have their ISO 27001 to implement in the rest of the organisation?
  • Risk treatment and SOA

    I have a question about the Statement of Applicability from the ISO 27001 and a question about the Risk Treatment Table from the ISO 27001.