Hi there. Could you please explain the difference between the risk owner functional responsibilities and that of the asset owners'. Thank you!
Standards in ISO 27001 series
Just having a confusion please clear this: Deploying ISO 27001 will cover all Information Security, Network Security, Application Security , Management etc., OR a Separte ISO standard will be followed for each like ISO 27033 for Network Security, ISO 27034 for Application etc
Schedule for testing controls under ISO 27001
Do you provide any guidance documents or recommendations with regard to ISO 27001, 27002 as to the 'schedule or frequency' recommended for testing of required and recommended controls? I have not found any specific requirement beyond assuring presence and functioning either in what I have seen of ISO27001, NIST 800, OWASP or SANS? If you offer a template that suggests how frequently specific server logs should be examined as well as other controls that should be looked at I would recommend it to a client.
ISO 27001 related certifications
I am working as a Network Security Engineer and Our Company is looking forward to follow ISO 27001 Standard and get certified. Please guide us what about ISO Standard 27001 , how it will help specially in term of Security.
Requirements identification
How do I investigate requirements for Procedure for Identification of Requirements?
Scope definition
Thanks for your initiative to keep us active. I have a question, Can I limit my scope of certification of ISO27001 to Electronic Data? The scope of the certification is ““Confidentiality, Integrity and availability of electronic data; restricted access to electronic date.”
Timescale in risk treatment plan
Quick question on the timescales for treatment and the plan. We have identified the activities that need to be completed and put into the plan. Is the timescale for these remediation points the timescale that we are working towards for risk treatment?
Is ISO 27001 Risk Assessment Methodology applicable to ISO 22301
Is this ISO 27001 Risk Assessment Methodology template applicable to both ISO27001 and ISO22301? The questions (some of them) should surely be different.
ISO 27001 business value
I am looking for some use cases in which using ISO 27000:2013 could provide business values
ISO 27001-22301 Integration
Is there a guidance document which guides the integration of ISO 27001 & ISO 22301, similar to ISO 27013 (Guidance for the integration of ISMS & ITSMS)