ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • IT audits and CISO

    Good day, does the IT auditor audits the work of the information security officer?
  • Threats and vulnerabilities list

    Hi i have a question concerning the Threats and Vulnerabilities list, what you have is simply examples or they cover all the aspects?
  • The best way to perform the internal audit

    Currently we are doing our IT audits via Excel and we plan to replace Excel-based audits (Excel-List with all of the ISO 27001 chapters) via SharePoint (we would like to map/move the excel content to SharePoint tables). I am the opinion, that this is not the best way of doing IT audits according to ISO 27001. So I would like to know if there are better solutions?
  • Risk interviews and workshops

    I have been reading the article on "risk assessment tips for smaller companies", again a very good article - very informative. In the article it refers to the risk assessment interview, do you have any examples of these interviews or scripts that could be used? Just to ensure we are asking the right questions and probing for the right information?
  • Impact and likelihood values

    i have a query. we have putforth threat and vulnerbaility values in risk assessment. we have values before mitigation and after mitigation. which value remains constant after mitigation? isit threat value or impact value​
  • Application risk assessment

    Would you please help me to understand about application risk assessment?
  • System access by the security guard

    Just need one clarifications, can the system access be given to the security guards?
  • Structure for a project plan

    Would you please guide me how to make a structure and logical project plan for implementing ISO 27001:2013 ?
  • Existing controls decrease the level of risk

    I did the risk assessment and go the risk level for every asset. Then the current controls maturity were evaluated accordingly to the CMM levels. The risk scale is from 0 to 4 and the acceptance level is below 2. The controls recude the current risk to below 2 level, so there is not need for a risk treatment plan. This is correct? or I'm missing something?
  • Guide for Indicators and risk assessment

    Hello, my question is if ISO 27001 has a indicator guide with formula for assessment every domain or control in a organization ?