Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... p>... d by top management.
What are your thoughts re this please?
ÃÂ
Answer:
I think that your approach (strategic and operational risks) is correct, according to ISO 27000:2014, the risk owner is ÃÂperson or entity with accountability and authority to manage a riskÃÂ.ÃÂ
For more information about this, please read this article ÃÂRisk owners vs. Asset owners in ISO 27001:2013ÃÂ : https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
... or Course vs. Lead Implementer Course  Which one to go for? : https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
2.- It depends on the company or the trainer, but I think that an estimation can be between $1.000-3000 (40-50 hours)
3.- You can go to the lead auditor course
4.- There are different things. Professional Evaluation and Certification Board (PECB) is an American personnel certification body, while American National Standards Institute (ANSI) is the official US representative of the International Organization for Standardization (ISO) which is related to the certification of companies. So, if you are interested in a personal certification, you can perform a PECB official exam, and you will the accreditation of a US company. For more information about certification for persons vs. organizations, please read this article ÂISO 27001 certification for persons vs. organizations : https://advisera.com/27001academy/iso-27001-certification/
5.- Depends on the company. Probably in your country there are various companies that perform the course/exam that you want in a local language. Anyway, keep in mind that we have resources in various languages, for example you can see this free webinar ÂISO 27001 Lead Auditor Course preparation training : https://advisera.com/training/iso-27001-lead-auditor-course/
6.- ENISA is the European Union Agency for Network and Information Security, and I think that there you can find information about conferences: https://www.enisa.europa.eu
... p>... exam.
ÃÂ
Answer:
I suppose that you know that there are no accreditations for the Lead Implementer course, so maybe can be interesting for you the ISO 27001 Lead Auditor course, because it has accreditations. Anyway, we do not have specific information about the exam of the Implementer course, but I think that this article can help you ÃÂLead Auditor Course vs. Lead Implementer Course ÃÂ Which one to go for?ÃÂ : https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
... ... s or could recommend any other software?
ÃÂ
Answer:
Sorry but we do not have information about this tool, keep in mind that to have a tool in your Management System is not mandatory, anyway this article can be interesting for you ÃÂWhen to use tools for ISO 27001/ISO 22301 and when to avoid themÃÂ : https://advisera.com/conformio/blog/2021/06/24/toolkit-vs-conformio-which-is-more-applicable-for-my-company/
... recovery vs. Business continuity : https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/
Anyway, here you can find a template for the BCP, you can see a free version clicking on ÂFree Demo tab : https://advisera.com/27001academy/documentation/business-continuity-plan/ and for the Disaster Recovery Plan : https://advisera.com/27001academy/documentation/disaster-recovery-plan/
Also here you can find an article that wil l help you to write a BCP for your organization ÂHow to write business continuity plans? : https://advisera.com/27001academy/blog/2010/04/08/how-to-write-business-continuity-plans/
... ÂPCI-DSS vs. ISO 27001 Part 1  Similarities and Differences : https://advisera.com/27001academy/knowledgebase/pci-dss/ and ÂPCI-DSS vs. ISO 27001 Part 2  Implementation and CertificationÂ: https://advisera.com/27001academy/knowledgebase/pci-dss/
Regarding to the risk register, if you want, you can try our methodology, there are templates for that you want (you can see a free version of all templates clicking on ÂFree Demo tab): https://advisera.com/27001academy/documentation/Risk-Assessment-and-Risk-Treatment-Methodology/
... sk owners vs. Asset owners in ISO 27001:2013Â : https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
Por otra parte, también te recomiendo este artÃculo (también en inglés) "How to handle Asset register (Asset inventory) according to ISO 27001" : https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/
... recovery vs business continuity https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/
Can business continuity strategy save your money? https://advisera.com/27001academy/blog/2010/03/15/can-business-continuity-strategy-save-your-money/
Backup policy  How to determine backup frequency https://advisera.com/27001academy/blog/2013/05/07/backup-policy-how-to-determine-backup-frequency/
... ÂPCI-DSS vs. ISO 27001 Part 1  Similarities and Differences : https://advisera.com/27001academy/knowledgebase/pci-dss/ and ÂPCI-DSS vs. ISO 27001 Part 2  Implementation and Certification : https://advisera.com/27001academy/knowledgebase/pci-dss/
Unfortunately, we have currently no materials on SIEM/ISO 27044 - when we publish any such materials we will certainly let you know.