Guest
Our organization ERM & BCMS risk is 5 (impact) x 5 (likelihood), however the ISMS is 4 (impact) x 4 (likelihood), can we use both or it should be aligned. based on your audit experience, is it nonconformity or not.
I have been given a task to send a
Please let me have your thoughts and views on these, this project is based in *** and I have been given 3 weeks to send proposal to them.
Hi,
I am currently trying to compile a useful collection of legal requirements…
On your webpage you provide the titles of various laws.
Do you have a more specific collection that point towards the actual requirements for the isms.
I do not have the resources to read the texts and compile the specific information.
I am advising a *** company at the moment, as well as a ‘daughter company’ in the *** on ISO 27001. Just some questions:
1 - In the ***, there is only one person actively working, but he is (of course) also shareholder. Would it be okay if he does the internal audit? In ***, we want to have the CTO as internal auditor. He doesn’t have shares, but he is part of Management. Would this be okay?
2 - What would be the cost of an online training for these internal auditors?
1 - Is it a fundamental prerequisite for certification in the standard?
2 - How deep should the mapping and documentation for the scope be?
3 - Overall, I still have a lot of questions about the topic "Organization context" and everything it should cover ...
1 - É um pré-requisito fundamental para a certificação na norma?
2 - Quão profundo deve ser o mapeamento e documentação para o escopo?
3 - No geral, ainda tenho muitas dúvidas sobre o tópico "Contexto da organização" e tudo o que ele deve abranger...
Can you please explain me briefly how to perform the risk assessment for biometric data (GDPR), using a computer, one employee and a biometric reader (ISO 27001)?
I’m watching the “How to Write ISO 27001 Procedure for Corrective and Preventive Action” video tutorial, and there our document is missing parts that he demonstrates is in his document. For example, the 3.1 introduction is not in our document.
Can you please explain me briefly how to perform the risk assessment for biometric data (GDPR), using a computer, one employee and a biometric reader (ISO 27001)?