SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Accreditation body or certification body?

    I wanted to know how a company/firm can be an accreditation body to certify other or organizations. Could you please assist me in this, if you are aware of.
  • Mobile computing and teleworking

    I am confused by mobile computing and teleworking since mobile devices are used for teleworking and no need for special physical location for teleworking as in old days! Can you give me more clarification on this?
  • Is assessing asset value mandatory?

    I happened to listen to the recording of your webinar on 'Basics of RIsk Assessment and Treatment'.
  • Perform a course?

    Regarding the LI and LA. I am not attending formal training. The people over at ITGOV are allowing me to take the exams from home (moderated by webcam) so long as I read the IT GOV 6th Edition and the ISO 27001/2 standards. In your experience, will the above - coupled with many years it IT security experience - be sufficient to take on these exams? Also, is there anywhere I can view example questions, just to be sure my study approach is sufficient (I don't want to waste the exam fee if I can avoid it).
  • Diagram of ISO 27001 and ISO 22301 implementation

    Could you please provide us an end to end flow diagram of steps/ phases in order to plan an ISO 27001 and ISO 22301 implementation exercise.
  • Audit the entire standard?

    How can audits be planned to cover the entire standard? Is there an accepted way to sample different portions of the standard over cycles? (Ex. how can all 133 controls be audited each time without missing other areas of the Standard?)
  • ISO 27001 and SOC report / audit

    How this ISO standard relates to the Trust Service Principles as applied in SOC report / audit? What resource can be shared between the two?
  • Best practices for asset identification

    My question was about best practicies of assets identification, and in my practice, interviewing with personal is almost the last part of the long and complex process of assets identification. I was wondering what is your opinion about it and your methods of assets identification.
  • Documenting the measurement of controls

    I need a sample information security metrics sheet ..... As we are aware .... ISO 27001:2013 demands " documented " information on what controls the organization selects how u measure them and how they ultimately help to achieve the defined infosec objectives. I kindly request you to help me with Procedure document for Information Security Metrics and Measurement and associated template / XLS file for same.
  • ISO 9001 for the implementation of ISO 27001

    We are working with our sister company for NIST requirements, which we can translate to ISO 27001. However the sister company only has 9001 in place. Do you have any material to help us translate from 9001 to 27001?