Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... >... 01-annex-a-controls/" class="content-link Link" target="_blank" >https://advisera.com/27001academy/blog/2014/11/03/how-to-structure-the-documents-for-iso-27001-annex-a-controls/
By the way, in the Statement of Applicability you choose the ISO 27001 Annex A controls, not ISO 27002 controls - although, the controls are basically the same. This article will help you: ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
... doc control system, I am not sure what you mean, but the main purpose of the document control is not related to the continuity or recovery of the business, so your second sentence is not correct, and keep in mind that the business continuity plan, the disaster recovery plan and the recovery are different things, so for more information about this you can read this article ÃÂDisaster recovery vs Business continuityÃÂ :ÃÂ https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/
... ISO 27001 vs. ISO 27002Â : https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
And this free tutorial can be also interesting for you ÂHow to write the information Security Policy According to ISO 27001Â :Â https://advisera.com/27001academy/tutorial/free-tutorial-how-to-write-the-information-security-policy-according-to-iso-27001/
... isera.com/9001academy/what-is-iso-9001/ÃÂ
ÃÂMethodology for ISO 9001 Risk AnalysisÃÂ :ÃÂ https://advisera.com/9001academy/blog/2015/09/01/methodology-for-iso-9001-risk-analysis/ÃÂ
And also can be interesting for you this ÃÂISO 27001 vs. ISO 9001 matrix (PDF)ÃÂ, you can download it here :ÃÂ https://advisera.com/27001academy/free-downloads
... recovery vs Business continuity : https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/
You can also learn how to define the RTOs from this article "How to implement business impact analysis (BIA) according to ISO 22301" :Â https://adviser a.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/
And this article can be also interesting for you "Understanding IT disaster recovery according to ISO 27031" :Â https://advisera.com/27001academy/blog/2015/09/21/understanding-it-disaster-recovery-according-to-iso-27031/
... ss="content-link Link" target="_blank" >https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/
Generally the asset owner can be for example an IT administrator, and the risk owner can be the head of the IT department. For more information about the risk owners and asset owners, please read this article ÃÂRisk owners vs. Asset owners in ISO 27001:2013ÃÂ :ÃÂ https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
... p>... s needs, what should we implement? is it BCP or DRP?ÃÂ The tool is 2 powerful machines with real time data.
ÃÂ
Answer:
I am not sure what you mean, but generally the DRP is more focused to the IT infrastructure, so from my point of view if you have an IT tool maybe can be better implement the DRP. This article can be interesting for you ÃÂDisaster recovery vs Business continuityÃÂ :ÃÂ https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/