Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... or Course vs. Lead Implementer Course  Which one to go for? : https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
The best for you would be to contact some of the certification bodies in your country that provide such services, they will give you more detailed information about the course. Biggest certification bo dies are usually DNV, SGS, Bureau Veritas, and BSI - I'm sure at least one of them will be present in your country.
... p>... ou:
8 criteria to decide which ISO 27001 policies and procedures to write https://advisera.com/27001academy/blog/2014/07/28/8-criteria-to-decide-which-iso-27001-policies-and-procedures-to-write/
Major vs. minor nonconformities in the certification audit https://advisera.com/27001academy/blog/2014/06/02/major-vs-minor-nonconformities-in-the-certification-audit/
... individual staff members can be custodians.ÃÂ
It is also important to know the term ÃÂrisk ownerÃÂ (new term introduced in the new ISO 27001:2013), which in accordance with ISO 27000:2014 is a ÃÂperson or entity with the accountability and authority to manage a risk"). If you want to know more information about asset owners and risk owners, please read this article ÃÂRisk owners vs. Asset owners in ISO 27001:2013ÃÂ :ÃÂ https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
... ... ISO 27002.
Finally, these articles can be interesting for you:
"How to learn about ISO 27001 and BS 25999-2" :ÃÂ https://advisera.com/27001academy/blog/2010/11/30/how-to-learn-about-iso-27001-and-bs-25999-2/
"Lead Auditor Course vs. Lead Implementer Course - Which one to go for?" :ÃÂ https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
... sk owners vs. Asset owners in ISO 27001:2013Â : Â https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/Â
Answer 3: From my point of view it is better if you list the datacenter as facility asset. Here it is important to have an asset for the datacenter (type facility), because there are threats directly related to this type of asset (there are also other threats directly related to the servers), furthermore you need to ensure that your supplier contract discuss about risks and the mitigation of threats.
Answer 4: An approach can be: Identify the facility as an asset, and also the systems and information contained on it, because they are different type of assets and have different threats/vulnerabilities. Another approach can be: Identify an unique asset and assign to it all threats/vulnerabilities related to the facility, systems and information.
Finally, this article about the asset inventory can be interesting for you ÂHow to handle Asset register (Asset inventory) according to ISO 27001Â :Â https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/
... sk owners vs. Asset owners in ISO 27001:2013Â :Â https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
Answer 3: Yes, my recommendation is to review the main steps of the implementation process to know if all are completed. This article can be useful for you ÂISO 27001 implementation checklist : https://advisera.com/27001academy/knowledgebase/iso-27001-implementation-checklist/ You can also review if you have all mandatory documents required by ISO 27001:2013, so please read this article ÂList of mandatory documents required by ISO 27001 (2013 revision) : https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/
... ISO 27001 vs ISO 27002: https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/).
So basically you have 3 options:
1) Implement ISO 27018 only - you won't get certified and won't know how to manage the security, but you will have technical controls focused on the cloud
2) Implement ISO 27001 only - you will get certified and know how to manage your security, but you won't have the technical controls focused on the cloud
3) Implement both ISO 27001 and ISO 27018 - actually it's rather easy because ISO 27018 is a complement to ISO 27001/ISO 27002, and you'll get the best out of both standards.
... ntent-link Link" target="_blank">https://advisera.com/27001academy/free-iso-27001-gap-analysis-tool/
Regarding the differences between the Gap analysis and the risk assessment, basically the gap tells you how far you are from ISO 27001 requirements, while the risk assessment tells you which incidents can h appen, anyway this article can be interesting for you ÃÂISO 27001 gap analysis vs. Risk assessmentÃÂ :ÃÂ https://advisera.com/27001academy/knowledgebase/iso-27001-gap-analysis-vs-risk-assessment/