How do I investigate requirements for Procedure for Identification of Requirements?
Scope definition
Thanks for your initiative to keep us active. I have a question, Can I limit my scope of certification of ISO27001 to Electronic Data? The scope of the certification is ““Confidentiality, Integrity and availability of electronic data; restricted access to electronic date.”
Timescale in risk treatment plan
Quick question on the timescales for treatment and the plan. We have identified the activities that need to be completed and put into the plan. Is the timescale for these remediation points the timescale that we are working towards for risk treatment?
Is ISO 27001 Risk Assessment Methodology applicable to ISO 22301
Is this ISO 27001 Risk Assessment Methodology template applicable to both ISO27001 and ISO22301? The questions (some of them) should surely be different.
ISO 27001 business value
I am looking for some use cases in which using ISO 27000:2013 could provide business values
ISO 27001-22301 Integration
Is there a guidance document which guides the integration of ISO 27001 & ISO 22301, similar to ISO 27013 (Guidance for the integration of ISMS & ITSMS)
Importance of CIA aspects
The CIA of information security. Which one is the most important? Confidentiality, Integrity, or Availability?
ISO 27018 implementation
Thank you, can you please share the plan and process to implement ISO 27018?
Risk assessment details
1 - How extreme a risk assessment shall be identified?