SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

ISO 27001 & 22301 - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Treating server as a single asset or viewing it separately for hardware and soft

    If you identified an asset for example, an application on a server... Do you have to separate two assets or to treat as an single asset?
  • Assessing consequences in risk assessment

    Regarding consequences assessment - would you recommend assessing one value or split this factor basing on information security aspects or business consequences category? As I see reviewing some examples available on the Internet, sometimes people assess conseqences of loosing confidentiality, integrity or availability separately. The others assess separately financial conseqences, law and regulatory consequences, reputation consequences and so on.
  • ISO 27001 risk methodology and corporate guidelines according to ISO 31000

    If you have already a risk assessment methodology  as per ISO 27001, and another one for OHSAS18001, and you been requested to implement the ISO 31000 guidelines , is it needed to review the existing risk assessment methodologies and replace it with one corporate one as per ISO 31000? Or we can simply refer in our ISO 31000 manual to the other methodologies?
  • Context of the organization in ISO 27001

    What does it mean: context of the organization? The auditor want to see the context of the organization chapter in the isms. Can you help me, what to write in it?
  • Difference between A.8.1.3 and A.8.2.3

    What is the difference between A.8.1.3 Acceptable use of assets and A.8.2.3 Handling of assets?
  • Sharing a server cabinet - is this compliant with ISO 27001?

    One of the business units which is not in our scope for accreditation is partially owned by ***. I know the particular business unit in question does not have access to our network at all but I am awaiting confirmation as to whether we share a server cabinet with them. I don’t think this is the case but if we do, can you please advise if this may hinder our compliance with any of the standards?
  • ISO 27001 Risk Management

    I’d like to ask a question about risk management process in ISO 27001. During risk management process; we determine risks, analyze their impact and likelihood, choose a risk treatment option and at last choose a control against that risk.
  • Difference Between ISO 22301 & ISO 22316

    Is there any major difference on ISO 22301 & ISO 22316. I understand ISO 22301 is certification standards and ISO 22316 is Guidelines for planning Organization resiliency.
  • Recertification or surveillance audit?

    Our organization got certified as ISO 27001:2005 in April'2014. But now
  • Annex SL Implementation for ISO 27001:2013

    Need your guidance around Annex SL in conjunction with ISO 27001. Particularity can you please provide me detail documentation or white paper around "how to implement ISO 27001:2013 using Annex SL. OR. how to leverage Annex SL to implement ISO 27001:2013 frame work.