Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Group of assets


    I have a question about listing assets for the risk assessment.  Is it acceptable to list similar assets under a single asset item (e.g. "laptops") instead of listing every item individually?

    Assuming this might be ok, is it then acceptable to add more specific items to the same list.  E.g. "All Dell laptops" or "Jane Smith's laptop"? Otherwise it seems that the list of assets and risk assessment items could easily grow to impractical or unmanageable proportions.

     

    Answer:

    Yes, you can create group of assets, for example “laptops” if they have the same threats/vulnerabilities and also the same risk. Regarding your second question, you need to take care, because you can have laptops –located in others facilities or other companies- which can have different threats/vulnerabilities and risks, so in this case you cannot include them in the same group “laptops”. It is also important to think about the data that the laptop has: If Jane Smith is for example the head of HR Department, maybe has confidential information (which is not in oth er laptop) and is critical for the business. So from my point of view in this case will be better to have an individual asset.
    This article can be interesting for you “How to handle Asset register (Asset inventory) according to ISO 27001” : https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/
  • Many documents


    I am conscious that this process generates a lot of paperwork, and one of the push backs from the business is that it will become too cumbersome to manage and things will get missed / ignored because it is unrealistic to maintain and make people aware of everything.  Ultimately, we don’t want this just to become a tick box exercise and lose sight of why we are doing it.  I would be interested in knowing how other companies have addressed this i.e. have they consolidated all the documents into a single document or grouped certain policies and documents together?
     

    Answer:

    Generally the number and complexity of documents is adapted to the particular needs of each company, please read this article for more information “8 criteria to decide which ISO 27001 policies and procedures to write” : https://advisera.com/27001academy/blog/2014/07/28/8-criteria-to-decide-which-iso-27001-policies-and-procedures-to-write/
    By the way, in accordance with ISO 27001, there are some mandatory documents, you can see the list here “List of mandatory documen ts required by ISO 27001 (2013 revision)” : https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/
  • Questions for HR team during the Internal Audit


    Can you please give me some ideas on what kind of questions can be asked while I perform the internal audit to the HR team, Testing team
     

    Answer:

    Generally you need to verify if the HR team is compliant with the domain "A.7 Human resource security” , which is included in the Annex A of ISO 27001:2013, and is composed by the objective control "A.7.1 Prior to employment", "A.7.2 During employment" and "A.7.3 Termination and change of employment". In some cases, can be also necessary ask to them questions related to legal obligations (domain A.18), if the HR team is responsible for these issues.
    So basically you need to ask questions related to the compliant of controls included in the domain “A.7”. 
    Finally, this article can be interesting for you “How to make an Internal Audit checklist for ISO 27001 / ISO 22301” : https://advisera.com/27001academy/knowledgebase/how-to-make-an-internal-audit-checklist-for-iso-27001-iso-22301/
  • Data center relocated


    Our data center relocated from one place to another, Can you have any check list through which we assess DC Migration, OR Post DC Migration checklist.
     

    Answer:

    I am not sure what you mean, but we do not have this specific checklist. Anyway, if you have relocated your data center, generally it is recommendable to perform again the risk assessment & treatment. You can use our methodology for this, which is composed by a Risk Assessment Table, Risk Treatment Table, Risk Assessment and Treatment Report, Statement of Applicability and Risk Treatment Plan. You can download a free version of our Risk Assessment Toolkit clicking on “Free Demo” tab here “ISO 27001/ISO 22301 Risk Assessment Toolkit” : https://advisera.com/27001academy/iso-27001-22301-risk-assessment-toolkit/ 
    We also have a checklist for the internal audit "Internal Audit Checklist" : https://advisera.com/27001academy/documentation/internal-audit-checklist/
  • Legislation starter list


    do you have relevant legislation starter lists ? 
     

    Answer:

    Yes, we have an article where you can find a list of laws and regulations related to information security of various countries. You can see it here “Laws and regulations on information security and business continuity” : https://advisera.com/27001academy/knowledgebase/laws-regulations-information-security-business-continuity/
  • Implementer training for ISO 27001


    I was wondering if you might have recommendations for implementer training for ISO 27001? My employer is pondering pursuing certification and I've not fully kept up with the standard the past few years. I did implementer training via BSi about 10 years ago, but things have obviously changed since then. Also, the BSi training was quite boring.
     

    Answer:

    There are many entities, mainly certification bodies like BSI, that has courses about ISO 27001 Lead Implementer (and also ISO 27001 Lead Auditor). Examples: Bureau Veritas, AENOR, SGS, etc.
    Our recommendation is that the company that offers the course has an accreditation (for example IRCA). Anyway, this article can be interesting for you “How to become an ISO 27001 / ISO 22301 consultant” : https://advisera.com/27001academy/blog/2014/07/21/how-to-become-an-iso-27001-iso-22301-consultant/ 
    Finally, maybe can be interesting for you to know changes in the new ISO 27001:2013, so this article can be interesting for you “Infographic: New ISO 27001 2013 revision – What has changed?” : https://advisera.com/27001academy/knowledgebase/infographic-new-iso-27001-2013-revision-what-has-changed/
  • Exclude controls


    The scope of our certification is IT Customer Operation Department – including Internal IT, Engineering and Infrastructure…  HR and Legal are excluded from the scope. My question is if I can exclude all the controls which are in their responsibility for example Securing Offices, Disciplinary Process or Identification of applicable legislation…
    Thank you in advance for your opinion,
    One more question do you also offer consultation?
     

    Answer:

    You can exclude controls only if there are no risks which would require such controls. So if after the risk assessment & treatment you do not need these controls to reduce risks, you can exclude them. 
    Anyway, from my point of view generally you cannot exclude controls related to compliance, laws or applicable legislation, because they are requirements of the business. 
    This article can be interesting for you “ISO 27001 risk assessment & treatment – 6 basic steps” : https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/
    And also this article “How to defin e the ISMS scope” : https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
    Regarding your last question, yes we offer consultant services for the implementation of ISO 27001 in your business if you buy our toolkit, although you can also ask us questions related to ISO 27001 and/or ISO 22301 without cost.
  • PECB, IRCA, ISO and RABQSA


    There are many organization issued ISO 270001 Certification like PECB, IRCA , ISO and  RABQSA. Which  one is the best?
     

    Answer:

    They are different things (PECB, IRCA, ISO and RABQSA). Certification bodies can issue a certificate of ISO 27001 for a company; some certification bodies: PECB, Bureau Veritas, BSI, AENOR, SGS, etc. But IRCA, ISO or RABQSA are not certification bodies that can issue certificates for companies, although IRCA and RABQSA can certify individual professionals (ISO 27001 Lead Auditor, Lead Implementer, etc).
    So basically a certification body (for example PECB) can certify companies in ISO 27001, but these entities need to be accredited in each country by an accreditation body (In United Kingdom for example is UKAS : https://www.ukas.com). 
    Also it is important to know that ISO is not a certification body, neither accreditation body, it is only a standardization body that develops and publishes standards (ISO 27001, ISO 22301, ISO 9001, etc).
    To know what is the best certification body for your business, there ar e some parameters like reputation, accreditation, etc. For more information please read this article “How to choose a certification body” : https://advisera.com/blog/2021/01/11/how-to-choose-an-iso-certification-body/
  • Activity Recovery Plan Section 8

    I'm sorry for responding this late.

    I didn't quite understand your question - in our template, we have "Recovery steps for the activity" in section 6, and section prior to this is called "Necessary resources".

    In any case, in the "Recovery steps" section you should describe exactly what your employees will need to do to resume their business operations - e.g. travel to the alternative location, purchase missing equipment, find additional human resources, restart key software applications, return all the data from the backup, test is some data is missing, etc.
  • System admin requires ISO 27001 certification?


    hi, i am working as manager system admin and having 14 years operations experience, can you share the justification that why system admin require ISO 27001 certification and training and how this course help them to implement best practices and compliance up to mark.
     

    Answer:

    It is not established in ISO 27001 that a specific profile (system admin or any other) needs to have an ISO 27001 certification, but obviously if a company wants to implement ISO 27001 needs to have people with experience and knowledge about ISO 27001, so in this case it is necessary training about the standard for those people involved in the implementation (if they do not have the necessary knowledge), and can be interesting to obtain the ISO 27001 Lead implementer, although it is not mandatory.
    The course of ISO 27001 Lead Implementer will help to you employees to give them the necessary information to the implementation and to be compliant with the requisites of the standard in your organization, taking into account that ISO 27001 is a standard about Inform ation Security Management Systems. 
    To implement best practices about information security, the best is to have knowledge about ISO 27002, which basically is a code of best practices about information security, so if you are interested in best practices, it is better training about ISO 27002.
    Finally, these articles can be interesting for you:
    "How to learn about ISO 27001 and BS 25999-2" : https://advisera.com/27001academy/blog/2010/11/30/how-to-learn-about-iso-27001-and-bs-25999-2/
    "Lead Auditor Course vs. Lead Implementer Course - Which one to go for?" : https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
Page 1045-vs-13485 of 1128 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +