SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Secure Engineering Principles (control A.14.2.5)

    I read the article regarding Secure Engineering Principles (control A.14.2.5), but I did not understand what is actually expected by Auditors regarding this control
  • Risk Assessment Table

    I have a question about the Risk Assessment Table. In the Risk Assessment Table video, you mention merging the results of the assessments from various asset owners. Should the Risk Assessment Table list each item separately (e.g. "John's laptop", "Tom's laptop", "Eric's laptop"), or merge them into a single asset type (e.g. "Employee Laptops")?
  • The same document for different controls

    If there is a technical control that is applicable to multiple rows (i.e. A.12.4.1 and A.12.4.4...) , is the best practice to list it where applicable along with the relevant document control?
  • Risk owner's approval

    "6.1.3 (f) obtain risk owners's approval of the information security risk treatment plan and acceptance of the residual information security risks.
  • Information security at strategic level

    At a strategic level what would you say are customers top requirements for ICT and CyberSecurity?
  • Security measures

    The measures that are in this form should be determined by the customer, for example to what scope the customer wants to be certified. Or should the measures be determined by the certification body?
  • Document management in ISO 27001

    Hi, Im having trouble locating where it mentions in the 27001 standard with regards document management and control?
  • Information to capture external and internal issues

    how to capture those internal and external issues in the sense what information need to be captured?
  • Procedure for document and record control

    We have begin to create a Procedure for Document and Record Control and we have the following questions:
  • ISO 27001 record types

    When you refer to records in ISMS is it for security related records only or all types of records. Also do you consider checklists as records?