Previous versions need to be kept and archived/graveyarded. Is there a particular time that applies to this in which they need to be kept or is it indefinitely? Does version control apply only to public facing documents or all company wide?
UKAS and ANAB accreditation
When looking for an organisation to audit our company across both the UK and US (we also have an office in Romania) does it matter if they can only offer UKAS accreditation? Do you know how this will stand in terms of whether it will hold as much weight as the ANAB accreditation?
Physical security policy and malware policy
Please how is the physical security policy and malware security policy content inline with BSI 27001?
Questionnaire for ISO 27001
I am doing my project on managing security threats and vulnerabilities for an organization in my university.my project is about to produce questionnaire on ISO 27001 and insert it into a system.the staff of that organization willl answer the question to know which threats should be given more priority to defend. In my research ,i havent found any way to create the question. I hope that you can help me..thank you.
Recommendation about Business Continuity Management
I will make a recommendation about Business Continuity Management for my Corporate. My Corporate is a Datacenter. What standard i need to used? Is it ISO 22301 or 27001? Or I can combine both ?
Controls in SoA
Hi friends,
Your support with the following doubt: If in the Risk Management I didn't identified an ISO 27002 control like necessary, Can I to include that control in the SoA anyway, considering its implementation like 'best practice'?
Thank you.
Best regards
Cloud computing
Hi, Can you please let me know what we can use to secure cloud. I have some info about fedRAMP but its too strict. is there any doable and accessible standard available. How close is it with ISO 27001
Assets mentioned by the owner
I was asked a couple of days ago about how to make sure that the assets mentioned by the owner is truly a reliable one and how to distinguish it from other unreliable ones. Appreciate if you helped me in that matter.
Leadership and commitment and Planning - General
In which documents (from ISO27001 toolkit) should I address requirements from clause 5.1, clause 6.1.1 and clause 8.1 ?
Clauses and controls achieved by completing the disaster recovery plan
What are the clauses and controls achieved by completing the disaster recovery plan?