My Question is what are the lessons learned/key insights/war stories/top tips/key dos and don'ts when implementing ISO 27001.
A question about asset inventory
I understand the asset inventory is a mandatory document for ISMS based on 27001:2013, my doubt is, this inventory should be formalized and signed for the High Management?
Taking into account the existing controls during the risk assessment
I have a quick question regarding the risk assessment template that I got from you. During the assessment, where assess the impact and likelihood do I take into account the existing controls that I already have? If yes, then in the column existing control do I fill in in accordance to ISO 27002 controls? Please advise.
Certificate validation
our company get ISO 27001:2005 certificate in *** from CIS company. I don`t know that certificate is valid in ISO website (iso.org) or not. how to check ISO certificate validation for my company or my country?
Difference in business continuity in 27001:2005 and 27001:2013
What is the difference in regard with business continuity in 27001:2005 and 27001:2013 in Annex A. Many organizations think, that if implemented 27001, they also implement 22301.
Information Asset: Business Applications and their Scope
We are planning to implement ISO 27001 and the scope is our Data Center and IT department
Business Continuity Plan Template
Hello,
We have multiple IT projects in operations. I would like to know whether the business continuity plan template would be a single document to cover all projects, or would it be a document per project.
Secondly, how would the 1) Incident Response Plan and 2) Activity Recovery Plan be against each project (single document or unique per project).
And lastly, where would the detailed disaster recovery steps of the IT data center infrastructure go ? These are the steps that will be executed by the system, network and database admins to recover the IT setup.
Thanks.
Convincing top management about the ISMS implementation
1. Top management actually supports to ISMS because it's mandatory by law but their attitude is not supportive and also IT stuff. So how convince them that ISMS implementation is important when actually really it is.
ISO 27002 clarification
I was recently informed that ISO27002:2013 has "2 Management Standards" within it === Is this true or False. If yes can you kindly confirm what they might be and how the standard is split as i have tried to do some research but CANNOT find anything pertaining to that fact.
BS 31000
Do you have a copy of the BS 31000 standard, what is it all about / what does it covers and why should information security care about it.