ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Business continuity management certification

    1 - Must we adhere strictly to iso 22301 methodology/ framework before implementation can be certified as meeting the standard?
  • Organizational context identification

    My main 'job' is to find out where my organization stands and what they should do in order to get ISO27001 certified. Do you have any tips or directions or questions that I should keep in mind while trying to gather as much information about the company as possible?
  • ISO Internal auditor vs Certified internal auditor

    I'm currently busy preparing for my CIA exams. However, once I finish those I will definitely want to top that up with the ISO Internal Auditor certification. How recognized is it internationally compared to CIA (Certified Internal Auditor) and how much is the certification?
  • HIPAA Compliance

    this is my assigmnt to find out is google fit s health and microsoft vault either comply with HIPAA standard security awarness and traning so kindly if you provide answer of this question?
  • Information and Cloud security policies

    Can you please explain the difference between Information security policy and cloud security policy?
  • Internal audit

    1. Do you have an anonymised example for the annual internal audit program? Am looking to see how much information is needed.
    2. Also when considering who performs the internal audits – do they have to be certified to do so?
  • Identifying Legal Requirements

    1 - How do I define the List of Legal Regulatory Contractual and Other Requirements? I read all the articles about it, but I still don't know how to define it. There's also no video tutorial on how to identify these requirements.
  • Qualitative and quantitative risk assessment

    What is the difference between qualitative and quantitative risk assessment, Please describe with an example…
  • Risk calculation and implemented controls

    I am working on a risk assessment and am confused by one thing. When I determine likelihood vs impact, should I determine those based on a total lack of controls or based on the controls we have in place currently?
  • Risk Assesment

    What is the difference between qualitative and quantitative risk assessment, Please describe with an example....