We have a project to determine the feasibility in convergence of ISO 27001 and ISO 22301 by creating a single policy for both standards. Alternatively we would like to create an overarching policy which would describe our process for both standards. Can you advise how this can be achieved and whether you have a toolkit which can assist with this goal.
HIPAA and ISO 27001
If an organization is already compliant to HIPAA, and is considering ISO 27001 compliance, how can they leverage their HIPAA compliance to speed up ISO 27001 compliance (e.g. is there a mapping available)?
BIA and risk assessment
1 - The BIA includes a risk assessment?
2 - Should The BIA questionnaire be different for every business unit into the company?
ISO 27001 clause 7
I did not find any article on the site advisera.com/27001academy on the clauses 7. Support, 7.1 Resources and 7.2 Competence. I have difficulty interpreting these clauses. Can you help me?
Auditor support material
I have done my ISO 27001 Internal Auditor course through your company. I was wondering if you might be able to assist me with a template or report structure that i could use as i need to do an assessment for one of our clients.
Inventory of assets
1 - I am filling the Inventory of assets as per the ISO 27001 toolkit template. I tried to access to the "How to handle Asset register according to ISO 27001 link but unfortunately couldn't as data was not found.
Root cause analysis on ISO 27001
We received this question: Are root cause analysis is not mandatory on ISO 27001:2013?
Clean desk procedure
Tomando a iso como base, é necessário um procedimento de mesa limpa ou só a politica assegura o processo? (Taking the ISO as a basis, is a clean table procedure required or is the policy alone the process?)
Why implementing ISO 27001?
Why any type of enterprise should implement the ISO 27001? even when they don't feel danger at all?
ISO 27001 ISMS into ISO 13485 QMS
If an organization already has an ISO 13485 QMS, and is considering ISO 27001 compliance, is there a best practice that recommends integration of an ISMS into the QMS, or is it better for the ISMS and QMS to be separate?