Search results for "iso17025 vs gmp"

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Clause vs related control or vice-versa

     Is it possible for you to provide me with a guide re above subject? Basically, a table or an Excel file mapping Clauses vs Controls for ISO 27001:2013. Does such a thing exist?
  • Some questions about ISO 27001:2013


    The purpose is to define a person or entity with the accountability and authority to manage a risk (this a definition that you can find in the ISO 27000:2014). And to determine the risk owners you should aim for someone who is closely related to processes and operations where the risks have been identified. Please read this article for more information “Risk owners vs. Asset owners in ISO 27001:2013”: https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/

     

    Is a communication plan mandatory in the ISMS documentation ? (clause 7.4)

     

    Answer:

    No, it is not mandatory. You can find a list of mandatory documents here “List of mandatory documents required by ISO 27001 (2013 revision)” : https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/. 

     

     The objectives mentioned in clause 6.2, does it refer to the objectives in the Statement Of Applicability (e.g. : in my company, we chose the whole Annex A for our SoA) 

     

    Answer:

    The objectives in ISO 27001 clause 6.2 can be set both for the whole ISMS, and/or for the control objectives in the Statement of Applicability - usually, the objectives are set at two levels: (1) the general ISMS level, and (2) at the level of security processes or security controls. See also this article: ISO 27001 control objectives – Why are they important? https://advisera.com/27001academy/blog/2012/04/10/iso-27001-control-objectives-why-are-they-important/
  • Incident Handling Procedure and Business Continuity Plan

    ... ter”, but we can consider that is the same or similar to a crisis or emergency. So, an incident can result in a disaster. 
     
    Generally, Disaster is related to the concept “Disaster Recovery” (technology), which is not the same that "Business Continuity" (whole organization). If you want to know the differences about this, please read this article “Disaster recovery vs Business Continuity": https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/

  • Difference between Incident and Disaster

    ... ster”, but we can consider that is the same or similar to a crisis or emergency. So, an incident can result in a disaster. 
     
    Generally, Disaster is related to the concept “Disaster Recovery” (technology), which is not the same that "Business Continuity" (whole organization). If you want to know the differences about this, please read this article “Disaster recovery vs Business Continuity": https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/

  • Implementation guidance ISO 27002

    ... he guideline. You do not have to apply everything that is written in ISO 27002; you have to apply only what ISO 27001 requires of you.

    Unfortunately, sometimes the certification auditors look towards ISO 27002, but you can clear this out very easily with them - simply ask them whether th ey think ISO 27002 is mandatory or not.

    This article will help you: ISO 27001 vs. ISO 27002: https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/

  • Information security policy vs. Acceptable use policy

    What is the big difference between the Information Security Policy and the Acceptable Use Policy?
  • ISO 27002 clarification


    First of all, ISO/IEC 27002:2013 is not a management standard - ISO 27002 is only a guideline on how to implement the security controls from ISO 27001. See also this article: ISO 27001 vs ISO 27002: https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/

    ISO 27001:2013 is a management standard, and it is the only management standard in the ISO 27k series. This 2013 revision of ISO 27001 had a predecessor (2005 revision of ISO 27001), so this might have caused the confusion.

    See also this article: Infographic: New ISO 27001 2013 revision – What has changed? https://advisera.com/27001academy/knowledgebase/infographic-new-iso-27001-2013-revision-what-has-changed/
  • Business continuity certifications for individuals

    ... ... rrently it is not clear which certification can bring you more benefits because BCI and DRII are established in the market for a very long time; however ISO 22301, similar to other ISO standards, is becoming more and more predominant, so I expect that in couple of years certifications related to ISO 22301 will have the best perspective.

    See also this article: Lead Auditor Course vs. Lead Implementer Course – Which one to go for ? https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/

  • KPI for IT Disaster Recovery

    ... ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/05/19/how-to-perform-training-awareness-for-iso-27001-and-iso-22301/
    You'll find quite good guidelines for testing & exercising in NFPA 1600 - see also this article: NFPA 1600 vs. ISO 22301 – Similarities and differences https://advisera.com/27001academy/blog/2013/11/05/nfpa-1600-vs-iso-22301-similarities-and-differences/

  • ISO 17799/27001/27002?


    ISO 17799 has changed it's name to ISO 27002 couple of years ago - therefore, these standards were the same.

    Here you'll find an explanation of differences between ISO 27001 and ISO 27002: https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/

    COBIT is a framework (not a standard) that is aimed at IT governance, therefore it is more IT related than ISO 27001.

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +