I’m trying to help customers start at SANS 20CSC and take their rather direct recommendations into something similar in ISO2700x. There is a mapping in SANS to 27002 but that kind of leaves me with the question of the mapping of controls from and to 27001
ISO 27001 project
1 - What are the most important assets we should focus on, in the Risk Assessment Table?
Mapping from ISO28001 to ISO27002
I need to understand if the is a direct mapping from ISO28001 to ISO27002, and the Annex and controls in the two standards? Is so where do I find that information please?
Benefits of certified auditor
Based on your experience, what are the benefits (beside the mandatory requirements) of having an internal auditor certified on 27001 in a company? I am a security consultant working for third party customers and I would like to go for the certification of 27001 as an internal auditor first since I think:
ISO 27035 and incident management
ISO 27035 is about incident response, but given that part 3 (which covers operations) hasn’t been published yet, is there much useful overlap? Does part 2 overlap with any of ISO 27001, or is a company better off not worrying about 27035 for the moment?
Risk assessment in ISO 22301
In implementing ISO 22301, can one adopt the risk module in ISO 27001 and treat the 5 elements the same?
Incidents and Non conformities
1 - Couple of employee are sharing the passwords among them and we have Password policy in place. what will you raise against them ? security incident or non conformance ?
When and where did ISO 27001 start?
When was ISO27001 initially implemented? Was it started in Europe?
Standards for preparedness against disasters
The 22301 relates to business development of s continuity. Do U know about Standards for the development of Preparedness Program for Natural Disasters?
ISO 27001 main deliverables
What are the main deliverables of ISO27001 related to the certification process and organizational benefits?