Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... cure-areas/
2 - if not, what standard should I look out for
For guidance on the implementation of ISO 27001 security controls, you should look for ISO 27002, which provides guidance on the implementation of ISO 27001 Annex A controls.
This article will provide you with further explanation about ISO 27002:
... does not require them to be classified, so you can adopt criteria that best fit your needs. Associating them to a risk level is an acceptable criterion. Certification audits adopt minor and major levels to classify nonconformities, and this is also an option for you.
This article will provide you with further explanation about the classification of nonconformities:
... our Air Traffic Control products I would hesitate to make this a requirement of your suppliers as some of them may not comply with AS9100. If you wanted to include certification to ISO 9001 or AS9100 to make it clear that either is acceptable, this would be my recommended approach.
You can learn a bit more about the differences in the standards in the article:
... 27001:2013 Annex A.17 controls you only need to document disaster recovery plans.
To see how a Disaster recovery plan compliant with ISO 27001 looks like, please take a look at this template demo: https://advisera.com/27001academy/documentation/disaster-recovery-plan/
This article will provide you with a further explanation of Disaster Recovery:
... sk owners vs. asset owners in ISO 27001:2013 https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
Regarding step 4, you do not need another SoA. Since you are extending the certification scope, a single SoA is sufficient.
For a company that has subsidiaries with different processing, is it ideal for them to have a general privacy policy or notice or entity-specific ones?
... ut selecting a certification body:
Yes, you can. This applies mostly to, for example, forms and procedures for internal audit, corrective measures, and non-compliant products.
On the following link you can find the article that compares ISO 9001 and ISO 13485:
... ... ses were not eliminated). In case they are solved as planned and there are no recurrences they will not mean a problem in the external audit. Â
Please note that ISO 27001 does not require non-conformities in internal audits to be classified. Normally non-conformities are classified during surveillance/certification audits.
For further information, see: