Use promo code:
CTA20

ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • BCP and DR

    This question is related to BCP and DR We have place to take the backup and store it in a external area ( working area). The backup will be done by a third party. Can we consider this as Disaster Recovery Site? IS it compulsary to have a disaster recovery site (Hot site, Warm Site & Cold Site)   Thanks, Vijay
  • Design the ISMS

     how to design the ISMS  for new ISO implementation?
  • Review of SOA after implementation

    Hello, I declare the status "Partially implemented" for some particular controls in SOA, for which I must write a Policy document. I put this task in Risk Treatment Plan, e.g.: write a Policy document. Is it necessary to review the SOA after implementation (after writing that Policy document) and update the status of controls to "Fully implemented"? Thanks, Cosmin
  • Conducting ISMS audit

     Hi, I would like to know the best way of conducting an ISMS audit and what to look for as an external auditor?
  • Process of implementation for ISO 27001

     We would like to start the process of implementation for iso27000 and need to know the cost of consultant to develop the procedures , time frame and certification cost
  • Asset inventory

    Who will be the business owner when asset inventory is to be made?
  • Section 9.1 - Monitoring, Measurement, Analysis and Evaluation

    I’m working on designing a way to monitor and measure the performance of our ISO 27001 and was unable to find any templates in the toolkit.  Is this incorporated in another document, or should a separate document required?
  • Documentacion para auditoria

     Buen día, quisera saber si voy bien con la documentación que el Auditor pedirá para la Certificación ISO 27001:2013
  • Storage of password

    What the ISO 27001 says about protection and storage of passwords, for example I have the passwords of a very sensitive server of the company and have to leave stored somewhere if someday I'm not available. The standard requires some action to it?
  • Keep information security

    Due to keep information security, we chose to use the sharepoint to store and share company information. To ensure that employees have adequate knowledge to handle the tool applied training. This training should be included in the registration Training and Awareness Plan?