SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Verification audit

    Do you know about any binding rule in the ISO27001-framework which states a deadline for having a follow-up /verification audit after a successful stage2-audit (here: after 12 months)? We wonder if the 12month period is starting with date of completion of the last audit or with the issuing date of the ISO certificate. It seems that there are different opinions on that deadline.
  • ISO 27001 business case template

    I have gone through the templates and they look good. However, I want to know if there is any sample business case as I need to make one for my company.
  • Risk owners vs asset owners.

    Hi there. Could you please explain the difference between the risk owner functional responsibilities and that of the asset owners'. Thank you!
  • Standards in ISO 27001 series

    Just having a confusion please clear this: Deploying ISO 27001 will cover all Information Security, Network Security, Application Security , Management etc., OR a Separte ISO standard will be followed for each like ISO 27033 for Network Security, ISO 27034 for Application etc
  • Schedule for testing controls under ISO 27001

    Do you provide any guidance documents or recommendations with regard to ISO 27001, 27002 as to the 'schedule or frequency' recommended for testing of required and recommended controls? I have not found any specific requirement beyond assuring presence and functioning either in what I have seen of ISO27001, NIST 800, OWASP or SANS? If you offer a template that suggests how frequently specific server logs should be examined as well as other controls that should be looked at I would recommend it to a client.
  • ISO 27001 related certifications

    I am working as a Network Security Engineer and Our Company is looking forward to follow ISO 27001 Standard and get certified. Please guide us what about ISO Standard 27001 , how it will help specially in term of Security.
  • Requirements identification

    How do I investigate requirements for Procedure for Identification of Requirements?
  • Scope definition

    Thanks for your initiative to keep us active. I have a question, Can I limit my scope of certification of ISO27001 to Electronic Data? The scope of the certification is ““Confidentiality, Integrity and availability of electronic data; restricted access to electronic date.”
  • Timescale in risk treatment plan

    Quick question on the timescales for treatment and the plan. We have identified the activities that need to be completed and put into the plan. Is the timescale for these remediation points the timescale that we are working towards for risk treatment?
  • Is ISO 27001 Risk Assessment Methodology applicable to ISO 22301

    Is this ISO 27001 Risk Assessment Methodology template applicable to both ISO27001 and ISO22301? The questions (some of them) should surely be different.