SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Asset value

    Please guide me. How to determine the asset value ? Is there any formula for that ?
  • Transition from BS 25999 to ISO 22301

    as an assignment i am looking to investigate the changes in BCM over the last ten years as a MSc Facilities Management assignment. Mainly my focus is the transition from BS 25999 to iso 22301. Any specific help in this direction would be appreciated.
  • Methodology for an IT audit

    I need to implement a new metodology for IT audit, special in the Aplication Controls. But for Applications Controls, only find information in COBIT, and I want to use ISO 27001. It is possible?
  • Guide for the implementation of ISO 27001

    Please can you talk me through email the step to step practical guide on how to implement ISO 27001 for a Medium size insurance company.
  • Approving the security policies

    I have a question on policy documents. Under the new ISO 27001 standard, there seems to be more and more policies needed - e.g. Cryptography, Suppliers policy, etc. Is it really necessary to consider these particular documents as policies per se, or can I consider these as guidelines only?
  • Methodology for risk assessment in ISO 27001

    Does ISO 27001 define a methodology for risk assessment? Give examples.
  • Question on List of legal, regulatory, contractual and other requirements

    We are a SaS company with a lot of customers, the most are in ***. To make this a little more complicated, we have Partners selling our product. With these partners we have separate contracts were we have defined the Information security responsibilities.
  • SoA and A.16 controls

    I've a question about SoA and A.16 controls. I can't justify the implementation of A.16 controls linking them to a specific risk. I think that the implementation of all A.16 controls is related to all risks, because we can use the lessons learned in incidents treatment to reduce the impact or probability of any incident in the future (which could be related to any risk).