Guest
I’m just started completing the template “Incident Management Procedure”. I would like to know, which “Confidentiality level” I need to write please ?
My company has achieve the Soc2 certification but I want to know, how can I use this to achieve ISO27001.
We are confused and ask for your clarification upon the found subject contradiction between ISO 27000 video tutorial 103: ISMS Policy and the Integrated ISO 27000/EU GDPR Toolkit.
The video tutorial is focused on the Information Security Management System Policy implementation based on a document template from the Toolkit. However, in the Integrated ISO 27000/EU GDPR Toolkit there is a document named Information Security Policy Integrated which content differs from that shown in the tutorial. ISMS Policy template is missing in Conformio too.
There is no video tutorial available for Information Security Policy implementation.
Are those policies different? Please be so kind to clarify the content contradiction between those two sources.
Does the person doing the Internal Audit need to have an IT Security Job Title or Role?
The PDF is only showing 1 page (essentially a cover page) and not all of the corresponding audit items and relevent details. Is this by design? Can the full audit details be exported to PDF or is this a bug?
Thank you. My training is going well. I'm so busy and can't take the training every day. The main thing - implementation.
1 - How to start ? What have to be done the first?
2 - How to start auditing the company on Information Security?
Currently, I have several questions regarding the business impact analysis questionnaire. Let me ask you below.
1. Should each process (activity) fill part 2 of the worksheet? Or maybe only those that were rated on a scale of 3 and higher in the course of the analysis and also those activities indicated as necessary for their functioning?
2. With reference to qualitative estimation. In your opinion, is it good practice to define the scale of financial losses as described below for general estimation (point no. 3 of the questionnaire)? Do you often use such a solution?
1 - less than 1% of monthly revenues
2 - 1-10% of monthly revenues
3 - 10-30% of monthly revenues
4 - over 30% of monthly revenues
3. If I add revenue ranges in point no. 3 of the questionnaire, should I do this also in point no. 10?
4. If I have 2 locations in my company that perform the same processes, but separately - independently - should I analyze them separately or collectively? How about averaging the data in one questionnaire?
Which document in iso 27001 matches a company Standard Operating Procedures?
Can I include information security objectives within the risk treatment plan? How should I include the information security objectives in the asset list and then assess the risks and treat them?