Does the scope statement needs to be updated? If not, will it be considered as a non-conformity
Differences between ISO 22301 & ISO 31000
Thank you for your email. Can you kindly tell me the difference between ISO 22301 & ISO 31000 2009, this is quite new to me (all l know is that they are both Risk Based)
Disaster Recovery Plan ISO 27001
There is a document - Disaster Recovery Plan 27001 - included in ISO 27001 Documentation Toolkit. This document cover the requirements from Annex A, i.e. A.17 Information security aspects of business continuity management ? In this case, in Statement of Applicability, is it right (and enough) to specify this document as Implementation Method for controls no. A.17.1.1, A.17.1.2, A.17.1.3 and A.17.2.1?
Clauses 4.1 and 4.2 in a software development organization
The only issue I am facing with new version is for clause number 4.1 "context or organization" and clause number 4.2 "interested parties concern". It will be very helpful if you explain with some example for a software development organization.
Riesgos y Declaracion de Aplicabilidad
Relacion entre el control documental de la ISO 27001:2005 e ISO 27001:2013
¿Qué relación existe entre el control documental de la ISO 27001:2005 y la ISO 27001:2013?
ISO 27001:2005 vs ISO 27001:2013
Liderar proyecto SGSI
Buenas tardes una empresa de caracter financiero que tiene un area de gestion de riesgos y otra de informatica quien debe liderar el proyecto SGSI, si las tareas son compartidas como debe hacerse.
Internal audit vs Gap analysis
What is difference between Fault finding and Gap analysis. Every external auditor would say that we do audit which is gap finding exercise and not fault finding exercise, I need clarity on the same.