ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Clauses 4.1 and 4.2 in a software development organization

     The only issue I am facing with new version is for clause number 4.1 "context or organization" and clause number 4.2 "interested parties concern". It will be very helpful if you explain with some example for a software development organization.
  • Riesgos y Declaracion de Aplicabilidad

  • Relacion entre el control documental de la ISO 27001:2005 e ISO 27001:2013

    ¿Qué relación existe entre el control documental de la ISO 27001:2005 y la ISO 27001:2013?
  • ISO 27001:2005 vs ISO 27001:2013

     
  • Liderar proyecto SGSI

     Buenas tardes una empresa de caracter financiero que tiene un area de gestion de riesgos y otra de informatica quien debe liderar el proyecto SGSI, si las tareas son compartidas como debe hacerse. 
  • Internal audit vs Gap analysis

     What is difference between Fault finding and Gap analysis. Every external auditor would say that we do audit which is gap finding exercise and not fault finding exercise, I need clarity on the same.
  • Keep documents

     Previous versions need to be kept and archived/graveyarded. Is there a particular time that applies to this in which they need to be kept or is it indefinitely? Does version control apply only to public facing documents or all company wide?
  • UKAS and ANAB accreditation

     When looking for an organisation to audit our company across both the UK and US (we also have an office in Romania) does it matter if they can only offer UKAS accreditation?  Do you know how this will stand in terms of whether it will hold as much weight as the ANAB accreditation?
  • Physical security policy and malware policy

     Please how is the physical security policy and malware security policy content inline with BSI 27001?
  • Questionnaire for ISO 27001

    I am doing my project on managing security threats and vulnerabilities for an organization in my university.my project is about to produce questionnaire on ISO 27001 and insert it into a system.the staff of that organization willl answer the question to know which threats should be given more priority to defend. In my research ,i havent found any way to create the question. I hope that you can help me..thank you.