Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... SO 27001 vs. ISO 27002â : https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
And also this article about the basic logic of ISO 27001 âThe basic logic of ISO 27001: How does information security work?â : https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/
Finally, our online course can be also interesting for you because we talk with more details about the ISO 27001 and the controls of the Annex A âISO 27001:2013 Foundations Courseâ : https://advisera.com/training/iso-27001-foundations-course/
... PCI-DSS vs. IS O 27001 Part 1 â Similarities and Differencesâ : https://advisera.com/27001academy/knowledgebase/pci-dss/
âPCI-DSS vs. ISO 27001 Part 2 â Implementation and Certificationâ : https://advisera.com/27001academy/knowledgebase/pci-dss/
Finally, our online course can give you information about the implementation of ISO 27001 in your organization âISO 27001:2013 Foundations Courseâ : https://advisera.com/training/iso-27001-foundations-course/
... 9001:2015 vs. ISO 9001:2008 matrix https://advisera.com/9001academy/free-downloads// that gives an overview of the differences between previous and current version of the standard.
My advice to you would be to preform the GAP analysis first to determine to what extent your organization is already compliant with the new requirements of the standard and what needs to be done to achieve the full compliance. Once yu determine what needs to be done, you can plan actions to address all these requirements. Here you can find our free GAP Analysis Tool https://advisera.com/9001academy/iso-9001-gap-analysis-tool/
... ISO 27001 vs. ISO 27017 â Information security controls for cloud servicesâ : https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
âISO 27001 vs. ISO 27018 â Standard for protecting privacy in the cloudâ : https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/
âWhat is ISO 22301?â : https://advisera.com/27001academy/what-is-iso-22301/
âWhat is ISO 20000â : https://advisera.com/20000academy/what-is-iso-20000/
2.- From my point of view, here is very important to establish a strong access control (if the questions are in paper format, you can use a safety deposit box, or if the questions are also in digital format you can use a Single Sign On, or a LDAP server and establish privileges for the access) and maybe cipher the information can be interesting for you (this is only for the digital information, and you can use for example BitLocket, or a TrueCrypt fork, or AES crypt, etc. There are many technologies for this).
3.- Both are the same from the information security point of view: devices that you use to access to information, and it is really the important, I mean, the information. So, in this case, if you want to improve your environment try to improve how the information is accessed (for example through a secure channel), instead to change one device for another.
4.- The virtualization is another way to manage information, and there are threats/vulnerabilities specifically related to this, but if you perform a risk assessment & treatment you can reduce risks related to this environments in the same way that in others environments. So, I am sorry but the virtualization does not increase/reduce the security concerns, simply is another scenario where there are risks that you need to manage. And ISO 27001 does not have specific security controls for virtualized environments, but there are security controls for any environment (including virtualized environments): access control (A.9 of Annex A of ISO 27001:2013), cryptography (A.10), operations security (A.12), communications security (A.13), etc.
This article related to the risk assessment can be interesting for you âISO 27001 risk assessment & treatment â 6 basic stepsâ : https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/
And our online course can be also interesting for you because we give more information about the risk assessment & treatment âISO 27001:2013 Foundations Courseâ : https://advisera.com/training/iso-27001-foundations-course/
... ... ore information, see:
- 7 steps in writing QMS policies and procedures for ISO 9001 https://advisera.com/9001academy/blog/2015/03/10/7-steps-in-writing-qms-policies-and-procedures-for-iso-9001/
- ISO 9001:2015 process vs. procedure â Some practical examples https://advisera.com/9001academy/blog/2016/01/19/iso-90012015-process-vs-procedure-some-practical-examples/
... sk owners vs. Asset owners in ISO 27001:2013â : https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
And our online course can be also interesting for you because we also talk about the risk owners âISO 27001:2013 Foundations Courseâ : https://advisera.com/training/iso-27001-foundations-course/