ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • 22301 certification

    We had ourselves certified according to ISO 27001 this year, which also includes a “small” BCM. How big is the additional effort if you want to be certified according to ISO 22301? So it's not the costs incurred by the certification body but rather the internal costs?

  • Toolkit documents

    Forgive my zero knowledge of ISO2001. I am doing the audit finding but didn’t find the template I needed in the Toolkit. 

    Example:- 

    Subject: Information security roles and responsibilities.
    Description: All information security responsibilities shall be defined and allocated.

    Thank you in advance.

  • Where is your Continual Improvement policy template?

    We bought your full 27001 toolkit but I can't find the Continual Improvement policy template.

    Most consultants think it is a mandatory doc, do you think it's not required for the certification?

  • Exclusions of the ISMS scope

    If a unit in the organization (let us say HR) is excluded from the scope, there is a dependency between HR and other units (for example, HR is responsible for recruitment and training). Although HR is excluded from the scope, it still provides training for employees of other departments that are included in the scope. In this case, HR should be considered an external third-party provider to the other organizational units that are included in the scope, which means that HR should be controlled as a supplier.

    What do you think?

  • Creating the Register of Legal, Contractual, and Other Requirements

    I'm in the process of creating the Register of Legal, Contractual, and Other Requirements.

    Q: how specific do I need to be? Is this where I list all our clients, suppliers, etc etc or do I give more top-line information and detail the specific interested parties later on?

  • TISAX and ISO 27001

    I hope this message finds you well. We are in plan to implement TISAX and ISO 27001. we have one IT staff member and there is a confusion on whether he should be sitting by himself in a secure office/area. My CEO requested to ask if the clauses or interpretations in either TISAX or 27001 specifically call for IT staff to have their own office area. Our Current IT staff is sharing the office with a member from purchasing department.

  • Security Awareness Training Records

    Is it compulsory to record attendance at this training? Would an ISO 27001 auditor require such a record?

  • Clarification Regarding Control Review Frequency in Policy Documents

    I wanted to clarify that all the policy documents we've prepared specify a requirement for a 6-month review. However, the specific controls we discussed are not mentioned in the documents. My question is whether, according to the policy, we need to review the controls every 6 months or if we have the flexibility to define the update frequency for the controls ourselves, separate from the document reviews. Please refer to the attached image for more details.

  • Risk levels and decision-makers

    About risk levels and decision-makers, could you share some insights? I got confused on who will be the decision maker on putting the level of the risk and based on which criteria the level was set?

Page 5 of 544 pages