Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... ss impact analysis must be reviewed.
However, once a year really is the best practice because of the following:
1) If you are ISO 27001 or ISO 22301 certified, the certification auditor will want to see those reviews at each surveillance visit (which happen once a year - see this article: https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/)
2) If you perform reviews less often, then you are in a danger that your RA / BIA will become too outdated because the pace of change (especially in IT) is really quick.
... sk owners vs. asset owners in ISO 27001:2013 https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
What has changed in risk assessment in ISO 27001:2013 https://advisera.com/27001academy/knowledgebase/what-has-changed-in-risk-assessment-in-iso-270012013/
... ISO 27001 vs. ISO 27002 (https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
1)Â Â Â Â There are, sadly, no controls on BYOD (understanding Âpersonal electronic devices brought at workÂ) in ISO 27002. You canÂt easily control it. The explanation in clause 6.2.1 (Mobile device policy) in ISO 27002 would help you further.
2)Â Â Â Â The only approach from ISO 27001 is risk management and defining the adequate policy. E.g.:
No classified information will be transmitted to and from BYOD equipment.
The use of BYOD to take pictures, audio and video recording must be authorised by the management.
The company will install software on mobile devices enabling it to delete the company information remotely.
3)    Risk management approach is described in ISO 27005. The main risks are: there comes Âprofessional information on a non controlled device through received emails, photos, videos and audio recording. Then: who may access this information around the user and what if itÂs lost or stolen?
Finally, youÂre right itÂs not a mandatory control. This blog post gives the point : List of mandatory documents required by ISO 27001 (2013 revision) - https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/
... >... popular ISO 27001 certificates are Lead Auditor and Lead Implementer - these articles will help you learn the details:
- How to become ISO 27001 Lead Auditor https://advisera.com/27001academy/knowledgebase/how-to-become-iso-27001-lead-auditor/
- Lead Auditor Course vs. Lead Implementer Course ÃÂ Which one to go for?ÃÂ https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
... ISO 27001 vs. ISO 27002 (103): https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
- MANDATORY DOCUMENTED PROCEDURES REQUIRED BY ISO 27001 (108): https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/
- How to maintain the ISMS after the certification (3): https://advisera.com/27001academy/blog/2014/07/14/how-to-maintain-the-isms-after-the-certification/
... ... f training services has signed a contract with the customer where it has obliged to comply with certain requirement, then it must comply with it - otherwise this is a nonconformity.
The point is, a company must comply with all of these: ISO 27001 + laws & regulations + contractual obligations + its own policies and procedures.
This article can also help you: Major vs. minor nonconformities in the certification audit https://advisera.com/27001academy/blog/2014/06/02/major-vs-minor-nonconformities-in-the-certification-audit/
... .. n-iso-27001/
ÃÂHow to identify interested parties according to ISO 27001 and ISO 22301ÃÂ: https://advisera.com/27001academy/knowledgebase/how-to-identify-interested-parties-according-to-iso-27001-and-iso-22301//
ÃÂRisk owners vs. asset owners in ISO 27001:2013ÃÂ: https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/