I am working in electrical distribution company looking forward to establish asset risk register where i have to design a risk assessment methodology for the our asset risk. I need your support of how to start and what are the best methodology which you think will suit our company?
Assessing risks for laptops as separate assets?
Consider the following: Laptop (CEO), Laptop (employee), Laptop (middle management). If I am considering e.g. the threat “unauthorized access to information” and “mobile equipment subject to theft” as vulnerability, the likelihood and the consequences are very different for these 3 types of employees. My question is: should I analyze them as different assets?
ISO 27003 for the implementation of ISO 27001
I am searching for guidance for implementing 27001. ISO 27003 is made for this purpose but for the ISO 27001 2005 version (not ISO 20013 version. How relevant is ISO 27003 now then the 2013 version is published and had there been conducted a mapping exercise which I can use to know what is relevant or not?"
ISO 27001 or AS ISO 27001?
I do have one question - I am going to purchase the standard and am not sure which one to get (and what the differences are). ISO 27001 or AU/NZS ISO 27001
Consultant career
I would like to have a baseline document on Information Security that could speak to all organization across the board whether it be finance, government, private sectors, etc.
Internal audit checklist questions
I had some questions regarding a few of the internal audit checklist items.
Implement ISO 27001 and ISO 22301
1. How long does it normally take to implement both of these (ISO27k + 22301) ones based on your experience?
Ejemplos para el alcance
Serian tan amable, de enviarme un par de ejemplos referentes a la Definición del alcance del SGSI, procesos y servicios, unidades organizativas , ubicaciones, redes e infraestructura, etc.
Time between 2 surveillance audits
Can you please tell me if there is a norm that defines the maximum period (one year) between two surveillance audits?
Implementing plan for PCI-DSS
Can you help me with a implementing plan for PCI DDS certification?