Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
What are the main diffrences between ISO 27001 and NIST? How can I know what is best for any organization?
Most changes in ISO 27001:2022 are related to Annex A, reorganizing controls from the 2013 version and adding 11 new controls. Contents of the ebook are still valid to help implement an ISMS ISO 27001 compliant.
These materials will give you an understanding of the changes:
For a new startup , we are hiring a CISO. At the same time we need help with the implementation of ISO 27001 as well. Is it fair to expect a CISO to implement new ISO policies, procedures, training, asset risks and risk maps. On a scale of 1-100, we are about 30 in terms of implementation. Question is do we still need a consultant for implementation. We are about to interview candidates for CISO, What can we ask him to convince ourselves that he can do both. Do they generally come with the implementation skill or they would be asking for an additional consultant
Appreciate some feedback on this. I enjoy reading your book a lot.
... . 500 employees because it would make your implementation unnecessarily complex.
You can access the ISO 27001 Gap Analysis Tool at this link: https://advisera.com/27001academy/free-iso-27001-gap-analysis-tool/
For further information, see:
- ISO 27001 gap analysis vs. risk assessment https://advisera.com/27001academy/knowledgebase/iso-27001-gap-analysis-vs-risk-assessment/
... ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
This material can also help you:
... t;
Regarding how long to operate the ISMS so as to have enough evidence to assess nonconformities, an operation period between 15 days and 1 month is a good starting point. Please note that security process cycles can vary (e.g., some processes are performed on a daily, weekly, or monthly basis). Â
For further information see:
... verify if it is registered there.
For example, certification bodies accredited to issue an ISO 27001 certification based in the US are registered with America’s national accreditation body (ANAB). At this site, you can identify the current valid certification bodies: https://anabdirectory.remoteauditor.com/
For further information, see:
... editation vs. certification vs. registration in the ISO world https://advisera.com/articles/accreditation-vs-certification-vs-registration-in-the-iso-world/
... outsourced through the distribution chain. When discussing the Quality Agreement, do we ask for one from the distributor or the actual manufacturer?
We sent one of the agreements to the distributor, and he answered (and, frankly, had a point) that since he is not a manufacturer, this is not a binding document, applicable to his relationship with us.
How to deal with distributor vs manufacturer quality agreements? Who shall provide us with the quality agreement?