Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... sk owners vs. asset owners in ISO 27001:2013â : https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
Regarding your second question, if there are no risks related to the development of software because there is no development in your company, you can exclude security controls related to the development, although there are some controls that are not only related with the development that you should consider to apply: A.14.2.5 Secure system engineering principles. For more information about this control, please read this âWhat are secure engineering principles in ISO 27001:2013 control A.14.2.5?â : https://advisera.com/27001academy/blog/2015/08/31/what-are-secure-engineering-principles-in-iso-270012013-control-a-14-2-5/
And in your specific case, during the risk assessment & treatment, you could identify if there are risks related to the connection with the SAAS provider, and if so, controls that you can use to reduce these risks are A.14.1.2 Securing application services on public networks, and A.14.1.3 Protecting application services transactions.
Finally, our online course can be interesting for you because you can find more information about security controls âISO 27001:2013 Foundations Courseâ : https://advisera.com/training/iso-27001-foundations-course/
... ISO 27001 vs. ISO 27017 â Information security controls for cloud servicesâ : https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
Finally, maybe our online course about foundations of ISO 27001 can be interesting for you âISO 27001:2013 Foundations Courseâ : https://advisera.com/training/iso-27001-foundations-course/
... ISO 27001 vs. ISO 27017 â Information security controls for cloud servicesâ : https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
And this article related to the basic logic of ISO 27001 can be also interesting for you "The basic logic of ISO 27001: How does information security work?" : https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/
And also this article about handling supplier security "6-step process for handling supplier security according to ISO 27001" : https://advisera.com/27001academy/blog/2014/06/30/6-step-process-for-handling-supplier-security-according-to-iso-27001/
... ISO 27001 vs. ISO 27017 â Information security controls for cloud servicesâ : https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
Finally, if you are interested in the security controls of ISO 27001, maybe our online course can be also interesting for you âISO 27001:2013 Foundations Courseâ : https://advisera.com/training/iso-27001-foundations-course/
... .. all requirements in ISO 20000, you can find it here: https://advisera.com/20000academy/iso-20000-documentation-toolkit
No, we don't offer certification, we are not certification body (see here to learn more https://advisera.com/blog/2016/02/29/accreditation-vs-certification-vs-registration-in-the-iso-world/)
... ISO 27001 vs. ISO 27017 â Information security controls for cloud servicesâ : https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
By the way, this article about how to handle an asset register, can be also interesting for you âHow to handle Asset register (Asset inventory) according to ISO 27001â : https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/
... 4001:2015 vs. 2004 revision â What has changed? https://advisera.com/14001academy/blog/2019/08/27/key-iso-14001-benefits-to-customers/nowledgebase/infographic-iso-140012015-vs-2004-revision-what-has-changed/
... sk owners vs. Asset owners in ISO 27001:2013â : https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
Finally, maybe our online course can be also very interesting for you because we also talk about the risk owners âISO 27001:2013 Foundations Courseâ : https://advisera.com/training/iso-27001-foundations-course/
... ISO 27001 vs. ISO 20000 matrix" https://advisera.com/27001academy/free-downloads/
Toolkits are available here:
ISO 20000 toolkit https://advisera.com/20000academy/iso-20000-documentation-toolkit
ISO 27001 toolkit https://advisera.com/27001academy/free-downloads/