Please let me where I could find the templates related to clause 4.1 and 4.4
Structure of the Risk Treatment Plan
Hi friends,
I have a doubt about the Risk Treatment Plan, How to structure it? For example, can I to organize the RTP according to risks? controls? assets? o according what?
Which columns should have it? and which is the best way to do this document according the ISO?
Thank you.
Quick Risk assessment
I have a document with many questions to check against my software, based in the controls of ISO. The System shall have a logoff button. So, I am compliant or not. If I am not compliant, so I need to do the risk for this item? Using the matrix to calculate. After do it for all items I did the risk assessment? Is it the correct why to do the risk assessment?
Business Continuity
I have a question, I´m going to work in process for business continuity (A.17.1.x), but I don´t have a clear idea for this process. Do you have any document or some guide that I can use for this part or just for the item A.17.1.2.
Disaster
a.- Do you have available articles, where you give your advice in how to define a disaster in a DR plan?
Asset management
Concerning my query on Asset Management
ISO 27001 on a personal level
I was interested to learn about iso 27001 on a personal level, but it is a bit much for a small organization with no formal security, no compliance requirements, and no desire to add security.
Clause 7.2
I noticed in the article indicated that the clause 7.2 is included in internal issues. I must prove that people involved in the implementation of the ISMS has competence to perform these tasks, or should I just have evidence that gave training to all company employees to become aware?
Your organization and your customer
Please, I would like to ask about ISO 27001. I have on doubt. For example, I selling a SYSTEM. So, my customer has whole infrastructure to support the SYSTEM that he bought from me. Servers, Storage, Network. I just create and install the SYSTEM on the customer environment. All management is customers own.
Implementation, maintenance and improvement of the ISMS
What would be resources for the implementation, maintenance and improvement are ISMS and which document I must inform you