Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... ... ar.ÃÂ
C - The recertification audit: It is performed only after the first initial certification audit and the surveillance audit, when the certificate expires after 3 years.
This is a cycle (A, B, C) that is repeated after the third year, but removing the first init ial certification audit.
For more information about this, please read this article ÃÂSurveillance visits vs. certification auditsÃÂ :ÃÂ https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/
... u ÂCISA vs. ISO 27001 Lead Auditor certification : https://advisera.com/27001academy/blog/2015/05/11/cisa-vs-iso-27001-lead-auditor-certification/
Generally ISO 27001 Lead Auditor is more easy and can help you to know basic concepts about information security, so my recommendation is that you can start with this. In this case, please read this article ÂHow to become ISO 27001 Lead Auditor : https://advisera.com/27001academy/knowledgebase/how-to-become-iso-27001-lead-auditor/
Point 2: IT auditors is more related to technology, remember for example CEH and CPTE. Regarding ISO 27001 Lead Auditor or consultants, please read this article ÂLead Auditor Course vs. Lead Implementer Course  Which one to go for? : https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
... https://advisera.com/27001academy/free-downloads/
Anyway, I think that this article can be also interesting for you ÃÂWhen to use tools for ISO 27001/ISO 22301 and when to avoid themÃÂ :ÃÂ https://advisera.com/conformio/blog/2021/06/24/toolkit-vs-conformio-which-is-more-applicable-for-my-company/
... recovery vs Business continuity : https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/
No obstante, puedes implementar tu plan basándote en tu negocio (y también en tu experiencia), aunque hay muchos escenarios que pueden ser comunes en cualquier situación (un ejemplo, el relacionado con la indisponibilidad de las personas/trabajadores).
Ten en cuenta también que la Continuidad de Negocio es tratada en profundidad en la ISO 22301, mientras que ISO 27001 está más relacionada con el Plan de Recuperación ante Desastres, lo cual está más relacionado con la infraestructura TI.
Por tanto, mi recomendación en tu caso es que uses el Plan de Recuperación ante Desastres porque es más "tecnológico", e igualmente puedes considerar el escenario relacionado con la indisponibilidad de tus empleados, pero creo que no es necesario que consideres el escenario relacionado con la publicación de información, porque no está directamente relacionado con la infraestructura TI. Pero importante, piensa que tus escenarios tienen que estar basados en los resultados del análisis de riesgos. También puedes ver nuestra plantilla (puedes ver una versión gratuita clickeando en "Demo gratis") "Ejemplos de escenarios de incidentes disruptivos"  https://advisera.com/27001academy/es/documentation/ejemplos-de-escenarios-por-eventos-de-interrupcion-del-negocio/Â
Finalmente, también puedes ver nuestro tookit de documentos de ISO 22301 aquÃ: https://advisera.com/27001academy/es/paquete-de-documentos-sobre-iso-22301/ o nuestro paquete Premium, el cual incluye documentos sobre ISO 27001 e ISO 22301 (recuerda que siempre puedes ver una versión gratuita clickeando en "Demo gratis"): https://advisera.com/27001academy/es/paquete-premium-de-documentos-sobre-iso-27001-iso-22301/
... r Course vs. Lead Implemented Course  Which one to go for? : https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
Finally, all our resources (articles, webinars, ebooks, templates, etc) will give you a knowledge about information security (and also business continuity) that you can use to acquire knowledge and become a consultant or lead auditor of ISO 27001. So, we recommend you to review all our resources, and please feel free to ask us any doubt.
... u ÂMajor vs. Minor nonconformities in the certification audit : https://advisera.com/27001academy/blog/2014/06/02/major-vs-minor-nonconformities-in-the-certification-audit/
Finally, regarding to the example of ISMS, you can see our templates (you can see a free version clicking on ÂFree Demo tab): https://advisera.com/27001academy/iso-27001-documentation-toolkit/
... ld. You can filter here by your country and the ISO 27001 (it is only available until year 2013): https://www.iso.org/the-iso-survey.html?certificate=ISO/IEC%2027001&countrycode=#standardpick
Also you can download a PDF with all results. Regarding 27001:2005 vs ISO 27001:2013, the lasts results of ISO are related to ISO 27001:2005, so maybe you will need to wait this year to see the number of ISO 27001:2013 certificates published in the world.