SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Difference in business continuity in 27001:2005 and 27001:2013

    What is the difference in regard with business continuity in 27001:2005 and 27001:2013 in Annex A. Many organizations think, that if implemented 27001, they also implement 22301.
  • Information Asset: Business Applications and their Scope

    We are planning to implement ISO 27001 and the scope is our Data Center and IT department
  • Business Continuity Plan Template

    Hello,  We have multiple IT projects in operations. I would like to know whether the business continuity plan template would be a single document to cover all projects, or would it be a document per project.  Secondly, how would the 1) Incident Response Plan and 2) Activity Recovery Plan be against each project (single document or unique per project).  And lastly, where would the detailed disaster recovery steps of the IT data center infrastructure go ? These are the steps that will be executed by the system, network and database admins to recover the IT setup.  Thanks.
  • Convincing top management about the ISMS implementation

    1. Top management actually supports to ISMS because it's mandatory by law but their attitude is not supportive and also IT stuff. So how convince them that ISMS implementation is important when actually really it is.
  • ISO 27002 clarification

    I was recently informed that ISO27002:2013 has "2 Management Standards" within it === Is this true or False. If yes can you kindly confirm what they might be and how the standard is split as i have tried to do some research but CANNOT find anything pertaining to that fact.
  • BS 31000

    Do you have a  copy of the BS 31000 standard, what is it all about / what does it covers and why should information security care about it.
  • Interested Parties and Their Requirements

    I have a few questions, it is about interested parties. I am in the process of gathering requirements of interested parties.
  • Do we need to place camera for server room?

    Do we need to place Camera for "server room"?Please suggest regarding this? And what are the things not keep in server room?
  • Not implementing 8.2

    Classification of Information)Is it possible to accept the risk that comes with not implementing 8.2 and still certify for ISO 27001? Background info: 'Shared Service' organisation that offers IT/Human Resources/ Facility Management to other organisations. There are no legal/contractual obligations known for labeling/classifying info.
  • Business continuity certifications for individuals

    I have a query regarding different certifications for individuals. I heard about various certifications such as CBCI (from BCI), CBCP (from DRII) and ISO 23301 Lead Implementer or Lead Auditor so which certification has more importance and what is the importance of going for them.