1 - On Appendix 3 – Internal Audit Checklist for ISO 27001 and ISO 22301 there is evidence column to fill. Based on document template, what can we fill on there column?
Security in SDLC
Are any ISO policies directly related to SDLC (requirements, plan, design, code, test, release) ? We want security testing built into the SDLC. Is it the A_14 Secure Development Policy?
ISO 27001 implementation project
Hi, I would like to create a project so it is clear for the company which steps they have to take and what they should do to get ISO 27001 certified. Can you help me with this?
Risk Assessment and Treatment
1 - For the Risk Assessment and Treatment report, do all of the identified risks have to be resolved/completed prior to certification or does having a timeline of completion okay.
Sensitive data back up
If you are in a diagnostic lab environment where you DO NOT want to back up customer sensitive data sent to you for troubleshooting and all systems are not production, is not doing a back up ok? We have an ondemand Virtual Machine environment that truly does not need back up.
ISO 27001 Consultant effort
Considering an ISO 27001 implementation project for a business works out to be 5 months:
Sample results of risk assessment
Can i get the example result of risk assessment?
ISO 22301 as part of information security audit
Can BCMS(22301) considered to be a part of Information security audit? Wanted to know if i22301 is also covered in information security audits.
ISO 27001 project schedule development
Is it possible to determine the time that is needed for each of the 16 steps individually?
ISO 27001 implementation phases
Utilicé la calculadora y obtuvimos: Estimated number of months required for implementation: 10 - Sin embargo, nos gustaría saber por su experiencia cuanto es el tiempo estimado para cada fase y así poder armar el plan proyecto y dar fecha estimada a la alta gerencia.