Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... . 500 employees because it would make your implementation unnecessarily complex.
You can access the ISO 27001 Gap Analysis Tool at this link: https://advisera.com/27001academy/free-iso-27001-gap-analysis-tool/
For further information, see:
- ISO 27001 gap analysis vs. risk assessment https://advisera.com/27001academy/knowledgebase/iso-27001-gap-analysis-vs-risk-assessment/
... ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
This material can also help you:
... t;
Regarding how long to operate the ISMS so as to have enough evidence to assess nonconformities, an operation period between 15 days and 1 month is a good starting point. Please note that security process cycles can vary (e.g., some processes are performed on a daily, weekly, or monthly basis). Â
For further information see:
... verify if it is registered there.
For example, certification bodies accredited to issue an ISO 27001 certification based in the US are registered with America’s national accreditation body (ANAB). At this site, you can identify the current valid certification bodies: https://anabdirectory.remoteauditor.com/
For further information, see:
... editation vs. certification vs. registration in the ISO world https://advisera.com/articles/accreditation-vs-certification-vs-registration-in-the-iso-world/
... outsourced through the distribution chain. When discussing the Quality Agreement, do we ask for one from the distributor or the actual manufacturer?
We sent one of the agreements to the distributor, and he answered (and, frankly, had a point) that since he is not a manufacturer, this is not a binding document, applicable to his relationship with us.
How to deal with distributor vs manufacturer quality agreements? Who shall provide us with the quality agreement?
... that by “Security Risk Management Plan” you mean for planning how to implement risk treatment.
Considering that, in your toolkit, there is a Risk Treatment Plan template where you can define what needs to be done to implement risk treatment. You can find this template in folder 07 Implementation Plan.
For further information, see: