Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... ISO 27001 vs. ISO 27016 - Information security controls for cloud servicesâ : https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
Maybe can be interesting for you the ISO 27018, although this standard is for protecting privacy in the cloud, so this article can be interesting for you âISO 27001 vs. ISO 27018 - Standard for protecting privacy in the cloudâ : https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/
And maybe our toolkit about the implementat ion of ISO 27001 and ISO 27017 can be also interesting for you (you can download a free demo clicking on âFree demoâ tab) âISO 27001 & ISO 27017 & ISO 27018 Cloud Documentation Toolkitâ : https://advisera.com/27001academy/iso-27001-iso-27017-iso-27018-cloud-documentation-toolkit/
... ... asking about the surveillance visit that is performed by the certification auditor, then this is the decision made by the certification auditor, not the company that has the certificate. They make such decision based on the importance of particular sites, and based on the fact where did they find most of the nonconformities during the previous visit.
See also: Surveillance visits vs. certification audits https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/
... 9001:2015 vs. ISO 9001:2008 matrix https://advisera.com/9001academy/free-downloads//
- Infographic: ISO 9001:2015 vs. 2008 revision â What has changed? https://advisera.com/9001academy/knowledgebase/infographic-iso-90012015-vs-2008-revision-what-has-changed/
- Free webinar â ISO 9001:2015 vs. ISO 9001:2008 â The main changes https://advisera.com/9001academy/webinar/iso-90012015-vs-iso-90012008-the-main-changes-free-webinar-on-demand/
... >
- Major vs. minor nonconformities in the certification audit https://advisera.com/27001academy/blog/2014/06/02/major-vs-minor-nonconformities-in-the-certification-audit/
- Surveillance visits vs. certification audits https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/
... ... our ISO 27001 blog https://advisera.com/27001academy/blog/ in couple of weeks - you can subscribe to the Newsletter and you will be notified automatically.
By the way, standard ISO 27018 is focused on personal data protection in the cloud - this article explains the details: ISO 27001 vs. ISO 27018 â Standard for protecting privacy in the cloud https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/
... ISO 27001 vs. ISO 27018 - Standard for protecting privacy in the cloudâ : https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/
And this article about information security controls for cloud services (everything, including your personal data is in the cloud), can be also interesting for you âISO 27001 vs. ISO 27017 - Information security controls for cloud servicesâ : https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
Finally, these materials will help you to know more about the information security:
- free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
- book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
... ce visits vs. certification auditsâ : https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/
âHow to maintain the ISMS after the certificationâ : https://advisera.com/27001academy/blog/2014/07/14/how-to-maintain-the-isms-after-the-certification/
"Accreditation vs. certification vs. registration in the ISO world" : https://advisera.com/articles/accreditation-vs-certification-vs-registration-in-the-iso-world/
Finally, these materials will help you to know more about information security and the audit s in ISO 27001:
- free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
- book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
... PCI-DSS vs. ISO 27001 Part 1 - Similarities and Differencesâ : https://advisera.com/27001academy/knowledgebase/pci-dss/
âPCI-DSS vs. ISO 27001 Part 2 - Implementation and Certificationâ : https://advisera.com/27001academy/knowledgebase/pci-dss/
Finally, these materials will help you to know more about the ISO 27001:
- free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
- book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
... to implement those because of time and budget restraints.
You have to make this planning very clear through the Risk treatment plan, and your risk owners need to accept the risks while those controls are not implemented.
The certification auditor will check whether you implemented those controls during the surveillance visits - see this article: Surveillance visits vs. certification audits https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/
... or Course vs. Lead Implementer Course - Which one to go for?â : https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
Finally, our ebook can be also very interesting for you: book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/