ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Security of remote access

    I have been researching for a presentation on remote access for the critical infrastructure industry such as water and utilities… I am trying to connect the standard to remote access considerations and am having trouble.. would you be so kind as to help me with my quest??
  • ISMS performance evaluation

    In ISO 27001:2013 point 9.1 is said org shall evaluate IS performance and effectiveness of ISMS and shall determine point a to f. In toolkit, can you give us specific what information or docs that can be as evidence and compliance about that points?
  • Risk assessment and risk registers

    hi i need assistance in doing risk assessments and risk registers coming up with risk appetite thresholds .to for a university
  • Information security standards

    What are all sec standards related to ISO or where can I find this info?
  • ISMS implementer and auditor

    Hi, I'm interested to do ISMS , I have exp 3.4 years in IT infrastructure. So I need some clarification how many years of exp needed to become isms then what courses want to do
  • Mapping between ISO 27001 and ISO 27002

    I’m trying to help customers start at SANS 20CSC and take their rather direct recommendations into something similar in ISO2700x. There is a mapping in SANS to 27002 but that kind of leaves me with the question of the mapping of controls from and to 27001
  • ISO 27001 project

    1 - What are the most important assets we should focus on, in the Risk Assessment Table?
  • Mapping from ISO28001 to ISO27002

    I need to understand if the is a direct mapping from ISO28001 to ISO27002, and the Annex and controls in the two standards? Is so where do I find that information please?
  • Benefits of certified auditor

    Based on your experience, what are the benefits (beside the mandatory requirements) of having an internal auditor certified on 27001 in a company? I am a security consultant working for third party customers and I would like to go for the certification of 27001 as an internal auditor first since I think:
  • ISO 27035 and incident management

    ISO 27035 is about incident response, but given that part 3 (which covers operations) hasn’t been published yet, is there much useful overlap? Does part 2 overlap with any of ISO 27001, or is a company better off not worrying about 27035 for the moment?