Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Kit documentacion


    ¡Hola! El kit de documentación que ofrecen incluye la implementación de los controles de la Norma ISO-27001
     

    Respuesta:

    Claro, nuestro toolkit incluye todos los documentos necesarios para la implementación de la ISO 27001 en tu organización. Esto significa que el toolkit tiene todos los documentos obligatorios, incluyendo aquellos relacionados con el PDCA y también aquellos documentos relacionados con los controles de seguridad, además incluye algunos documentos no obligatorios. Si quieres ver la lista de documentos obligatorios de la ISO 27001 (y no obligatorios), por favor lee el siguiente artículo "Lista de documentos obligatorios exigidos por la norma ISO 27001 (revisión 2013)" : https://advisera.com/27001academy/es/blog/2015/05/04/lista-de-documentos-obligatorios-exigidos-por-la-norma-iso-27001-revision-2013/
    En cualquier caso, ten en cuenta que que son plantillas, y necesitas adaptarlas a tu negocio, pero para ello puedes contar con nuestro apoyo. Puedes ver una versión gratuita de todos los documentos clickeando en "Demo gratis" : https://advisera.com/27001academy/es/paquete-de-documentos-sobre-iso-27001/
  • Auditor Lider ISO 27001


    Muy buenas tardes, ayer estuve presente en el webinar y me ayudo a sacarme varias dudas que tenía con respecto a la certificación de la iso27001.
    Te molesto para consultarte algo, hace rato que quiero hacer el curso de auditor pero no sé bien cual realizar. Las opciones que tengo es Auditor Interno o Auditor Líder.
    Específicamente lo que quiero hacer yo es poder realizar consultoría y auditorias apuntado todo a redes, sistemas de información y seguridad informática.
    Estoy dando vueltas hace rato sobre esto y no sé por dónde empezar, que capacitación tendría que realizar primero que otra.
    Espero que me puedas dar tu opinión para orientarme un poco ya que tenes mucha experiencia sobre este campo.
     

    Respuesta:

    Son 2 cosas diferentes: consultor y auditor, y creo que el primer paso es conocer en profundidad la ISO 27001. Para esto, puedes ver esta presentación gratuita (en inglés) “Why ISO 27001 – Awareness presentation” : https://info.advisera.com/27001academy/free-download/why-iso-27001-awareness-presentation/
    Este artículo sobre consultores también puede resultarte int eresante (en inglés) “How to become an ISO 27001 / ISO 22301 consultant” : https://advisera.com/27001academy/blog/2014/07/21/how-to-become-an-iso-27001-iso-22301-consultant/
    Después de esto, si tienes interés en auditar un SGSI, el próximo paso es realizar un curso para obtener la certificación en Auditor Líder, por tanto este artículo puede ser interesante para ti (en inglés) “How to become ISO 27001 Lead Auditor” : https://advisera.com/27001academy/knowledgebase/how-to-become-iso-27001-lead-auditor/
     También puede ser interesante para ti este Webinar gratuito (en inglés) “ISO 27001 Lead Auditor Course preparation training” : https://advisera.com/training/iso-27001-lead-auditor-course/
    Finalmente, en relación a las redes, sistemas de información y seguridad informática (esto no es lo mismo que la seguridad de la información), estas cuestiones están más relacionadas con la tecnología, y necesitarás cursos/certificaciones más especializadas, por ejemplo MCSA (Microsoft Certified Solutions Associate), CEH (Certified Ethical Hacker), LPIC (Linux Professional Institute Certification), etc.
  • Accreditation body


    My company (in Singapore) is interested in becoming a accredited body for ISO/IEC 27001. I did some research on my own and it seems that before I could apply for accreditation for ISO/IEC 27001, I would need to accredited for ISO 17201 before I could apply for ISO/IEC 27001. As I have been reading from many sites, it seems a little confusing and I was wondering if you could provide advises on how to become a accredited body for the mentioned ISO. In addition, could you please recommend any body that does such services.
     

    Answer:

    I think that you can not do it, because each country has a national accreditation body, and it tends to be a public entity (related to the government). In Singapore the accreditation body is this: https://www.sac-accreditation.gov.sg
    And also you can see the certification bodies accredited by SAC : https://www.sac-accreditation.gov.sg/accredited-org/certified-cab-companies
    Anyway, any company can achieve the ISO 27001 certificate (but it is a completely different thing), and for this, you need to implement the ISMS and after you need to choose a certification body. If you are interested about this, you can read this article "How to choose a certification body" : https://advisera.com/blog/2021/01/11/how-to-choose-an-iso-certification-body/
  • Clause 4.1 and 7.5


    Please explain clause 4.1 and 7.5. Problem is that our company has only three employees (including me) and i dont get the big picture of this clause 7.5 
     

    Answer:

    Sure, I will give you two interesting articles:
    Regarding to the clause 4.1 Understanding the organization and its context, you can read this article “Explanation of ISO 27001:2013 clause 4.1 (Understanding the organization)” : https://advisera.com/27001academy/knowledgebase/how-to-define-context-of-the-organization-according-to-iso-27001/
    Regarding to clause 7.5 Documented information, you can read this article “Document management in ISO 27001 & BS 25999-2” : https://advisera.com/27001academy/blog/2010/03/30/document-management-within-iso-27001-bs-25999-2/
    Finally, related to your final question “i dont get the big picture of this clause 7.5” : This clause (7.5) is related with the management of documents (you need to establish this controls for each document: identification, description, review and approval for suitability and adequacy, format, control of changes, control access, distribution, storage, retention, disposition, control of external documents). And as you know, there are some mandatory documents (if not, please read this article “List of mandatory documents required by ISO 27001 (2013 revision)” : https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/), so independently of the size of your business, you need to implement documents, and for them you need to establish controls that I have mentioned before.
  • Ebook for a network administrator


    I work as network administrator and I am looking If I get ebook to enhance my knowledge.
    I want to be an ISO 27001 consultant .
    Please advise 

     

    Answer:

    We have a great free ebook, which I think that can be very interesting for your job because it is related to the cybersecurity. You can find it here “9 Steps to Cybersecurity” : https://advisera.com/books/9-steps-to-cybersecurity-managers-information-security-manual/
    Finally, if you want to be a ISO 27001 consultant, maybe this article can be interesting for you “How to become an ISO 27001 / ISO 22301 consultant” : https://advisera.com/27001academy/blog/2014/07/21/how-to-become-an-iso-27001-iso-22301-consultant/
  • Examples for external documentation relevant to the ISMS

    Here are a couple of examples:

    Contracts with your clients
    Correspondence with third parties about the security issues
    ISO 27001 standard itself
    Manuals for security software / equipment
    etc.

    This article might also help you: Document management in ISO 27001 & BS 25999-2 https://advisera.com/27001academy/blog/2010/03/30/document-management-within-iso-27001-bs-25999-2/
  • ISO 9001 and ISO 27001


    which are all the similar clauses. i want these information bcz ISO 9001 has 8 clauses whereas 27001 has 10 so i m trying to make a single document out of it

     

    Answer:

    First of all, keep in mind that the ISO 9001 is being updated, and the final version is expected by the end of 2015. The structure of the new ISO 9001:2015 is more similar to the ISO 27001:2013 (has 10 clauses and with the same name, but obviously with different content). 
    Anyway, I think that this article can be very interesting for you “Using ISO 9001 for implementing ISO 27001” : https://advisera.com/27001academy/blog/2010/03/08/using-iso-9001-for-implementing-iso-27001/
    Finally maybe these resources can also be interesting for you :

    Webinar "ISO 27001 implementation: How to make it easier using ISO 9001" : https://advisera.com/27001academy/webinar/iso-27001-implementation-make-easier-using-iso-9001-free-webinar-demand/
    Article "5 Main Changes Expected in I SO 9001:2015 from the 2014 Draft International Standard (DIS)" : https://advisera.com/9001academy/knowledgebase/5-main-changes-expected-in-iso-90012015-from-the-2014-draft-international-standard-dis/
  • Reasons to get the certification


    I haven't had a chance to study the docs yet, but will within the next week or so. Our basic questions are: (1) would a certification be useful for our business? (beyond the obvious security benefits) and (2) if so, which certification? ISO, SSAE, etc.
     

    Answer:

    1) There can be various reasons to get the certification, here you can find more information about this “Should your company go for the ISO 27001 / ISO 22301 certification?” : https://advisera.com/27001academy/iso-27001-certification/
    2) ISO has more prestige at international level, so if you want a certificate with an international recognition, we recommend you ISO.
  • Server setting to be compliant for ISO 27001


    I am looking for server setting to be compliant for ISO 27001
     

    Answer:

    From my knowledge, there are no individual servers in, for example in a shop, prepared to be compliant with ISO 27001, because each company needs to configure it in accordance with their business, and also with the requisites of the ISO 27001. Maybe you can find a data center certified in ISO 27001, or a company selling servers, but also to be compliant to ISO 27001 you need to configure the server according to identified risks (establishing a control access policy, setting secure communications, cryptography, etc. )
  • Distance in the ISO 22301


    which part of ISO speak about the distance? We would like to reference to. ISO 22301

     

    Answer:

    There is no specific distance established in the ISO 22301, but there are best practices, so I think that this article can be very interesting for you “Disaster recovery site – What is the ideal distance from primary site?” : https://advisera.com/27001academy/knowledgebase/disaster-recovery-site-what-is-the-ideal-distance-from-primary-site/
Page 1064-vs-13485 of 1128 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +