Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... la organización (cláusula 4) y las acciones para abordar riesgos y oportunidades (cláusula 6.1), mientras que otros requisitos se han eliminado. Esto significa que será necesario redactar nuevos procedimientos pero que otros podrán mantenerse de manera similar. Para más información, vea: https://advisera.com/14001academy/es/knowledgebase/infografia-iso-140012015-vs-2004-que-ha-cambiado/
... p>... ng this, for your second question I can say yes, as a Cloud IaaS customer, your organization can benefit by extending you control environment to include recommendations from ISO 27018 with the purpose to have a better basis to evaluate security controls for PII implemented by your cloud providers.
This article will provide you further explanation about ISO 27018:
- ISO 27001 vs. ISO 27018 â Standard for protecting privacy in the cloud https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/
... recovery vs Business continuity https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/
- What to implement first: ISO 22301 or ISO 27001? https://advisera.com/27001academy/blog/2017/04/03/what-to-implement-first-iso-22301-or-iso-27001/
These materials will also help you regarding BCPs and DRPs:
- Book Becoming Resilient: The Definitive Guide to ISO 22301 Implementation https://advisera.com/books/becoming-resilient-the-definitive-guide-to-iso-22301-implementation/
- Implementing Business Impact Analysis according to ISO 22301 [free webinar] https://advisera.com/27001academy/webinar/implementing-business-impact-analysis-according-to-iso-22301-free-webinar/
... ISO 27001 vs. ISO 27018 â Standard for protecting privacy in the cloud https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/
- Catalogue of th reats & vulnerabilities https://advisera.com/27001academy/knowledgebase/threats-vulnerabilities/ (in this list you will find most threats and vulnerabilities that are applicable to PIA)
... >
- CISA vs. ISO 27001 Lead Auditor certification https://advisera.com/27001academy/blog/2015/05/11/cisa-vs-iso-27001-lead-auditor-certification/
- How to become an ISO 27001 / ISO 22301 consultant https://advisera.com/27001academy/blog/2014/07/21/how-to-become-an-iso-27001-iso-22301-consultant/
- How to become ISO 27001 Lead Auditor https://advisera.com/27001academy/knowledgebase/how-to-become-iso-27001-lead-auditor/
These materials will also help you regarding training resources:
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
- ISO 27001:2013 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/
... ISO 27001 vs ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
- Document management in ISO 27001 & BS 25999-2 https://advisera.com/27001academy/blog/2010/03/30/document-management-within-iso-27001-bs-25999-2/
These materials will also help you regarding document management:
- book Managing ISO Documentation: A Plain English Guide https://advisera.com/books/managing-iso-documentation-plain-english-guide/
- Free o nline training ISO 27001 Foundations Course
https://advisera.com/training/iso-27001-foundations-course/
... p>... ISMS scope), and a single certification may cover multiple locations, also called sites. For example, you can have an organization's HQ and its filial covered by a single ISO 27001 certificate, resulting in one certification and two sites.
This article will provide you further explanation about differences regarding certification and other related ISO terms:
- Accreditation vs. certification vs. registration in the ISO world https://advisera.com/articles/accreditation-vs-certification-vs-registration-in-the-iso-world/
... ssessment vs. business impact analys is https://advisera.com/27001academy/knowledgebase/risk-assessment-vs-business-impact-analysis/
- How to implement business impact analysis (BIA) according to ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/
These materials will also help you regarding risk assessment and BIA:
- Book Becoming Resilient: The Definitive Guide to ISO 22301 Implementation https://advisera.com/books/becoming-resilient-the-definitive-guide-to-iso-22301-implementation/
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
... NFPA 1600 vs. ISO 22301 â Similarities and differences https://advisera.com/27001academy/blog/2013/11/05/nfpa-1600-vs-iso-22301-similarities-and-differences/
- ISO 22301 vs. ISO 22313 https://advisera.com/27001academy/blog/2013/05/21/iso-22301-vs-iso-22313/
2. 5 elementos que deban considerarse para la implementación de un sistema de gestión de continuidad de negocio.
(5 elements that must be considered for the implementation of a business continuity management system.)
Answer: For a successful Business Continuity Management System implementation you should consider Business continuity policy, BIA, BC Strategy, BC Plans, and Exercising & testing.
3. 3 eventos que puedan afectar la continuidad de negocio de una institución bancaria?
(3 events that may affect the business continuity of a banking institution?)
Answer: Considering the interconnected banking industry today unplanned IT and telecom outages, cyberattacks and data breaches could be on many top 10 lists of disruptive events.
4. Que actividades y aspectos consideras que son necesarios considerar para la elaboración de un BIA?
(What activities and aspects do you consider necessary to consider for the development of an BIA?)
Answer: The establishment of a BIA methodology, engagement of top management, participation of processes key users, and the use of a facilitator with experience on performing business impact analysis. This is all covered in the webinar.
5. Por ejemplo si un incendio afectó las oficinas centrales de un banco un domingo por la madrugada. La situación es tan critica que ningún empleado puede ingresar al edificio. Considerando que el banco cuenta con un plan para este tipo de incidente, según tu experiencia que recursos, estrategias y actividades pueden estar detalladas en dicho plan?
(For example, if a fire affected the central offices of a bank on a Sunday in the morning. The situation is so critical that no employee can enter the building. Considering that the bank has a plan for this type of incident, according to your experience what resources, strategies and activities can be detailed in this plan?)
Answer: Considering this scenario, a strategy that should be considered is the definition of an alternative site from where people can initiate their work on Monday. Generally bank institutions have extremely short recovery times, so this alternative should be a warm or hot site. In terms of resources and activities, without further details it is not possible to define them, but generally speaking, you should consider transportation for employees, recovering of IT systems and databases, and communication with the media.
This article will provide you further explanation about Business Impact Analysis according ISO 22301:
- How to implement business impact analysis (BIA) according to ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/
This material will also help you regarding Business Impact Analysis according ISO 22301:
- Book Becoming Resilient: The Definitive Guide to ISO 22301 Implementation https://advisera.com/books/becoming-resilient-the-definitive-guide-to-iso-22301-implementation/