Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... e them, they will have different times for need (e.g., the office is necessary immediately after the incident, and employees will be necessary 2 hours after the incident).
This planning is useful when you do not have a hot site strategy implemented and the alternative infrastructure will be built after the incident.
For further information, see:
... process of an organization (section 9.6 Maintaining certification).
You can have an overview of this standard here: https://www.iso.org/obp/ui/#iso:std:iso-iec:27006:ed-3:v1:en
This article will provide you a further explanation about accreditation and certification:
... ation body:
... ontroller vs. processor – What are the differences? https://advisera.com/eugdpracademy/knowledgebase/eu-gdpr-controller-vs-processor-what-are-the-differences/
3 steps for data transfers according to GDPR https://advisera.com/articles/3-steps-for-data-transfers-according-to-gdpr/
If you need to understand how to implement EU GDPR compliance, you may consider enrolling in our EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course/
... or Course vs. Lead Implementer Course – Which one to go for? https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
2 - Also, having passed the exam can you state you are an "ISO27001 Lead Implementer" or do you need to demonstrate some level of practice in the industry (in the same way as the CISSP and CISM qualifications) to an overarching body?
I’m assuming that by overarching body you mean “certification body”, or a similar organization that is responsible for issuing the certification (like ISC2 for CISSP and ISACA for CISM).
Considering that, depending on the organization that is responsible for the exam, there may be other requirements to fulfill to be allowed to use the title "ISO27001 Lead Implementer". To know the specific detail you need to contact directly the exam provider.
For Advisera's ISO 27001 Lead Implementer Course, there are no additional requirements but attending the workshop and passing the exam.
... recovery vs Business continuity https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/
2 - I suppose our Head Software Developer who also is in charge of Server Maintenance, would that be the person to document these steps. As it is much more complex than just “copy-paste install backup.
The person to be involved in the development of a Disaster Recovery Plan will depend on the defined disruptive scenario.
For example, if the disruptive scenario involves only the loss of a server, then your Head Software Developer will be the person to be responsible for the plan. On the other hand, if the disaster involves not only the loss of the server, but also the loss of the server room, or an entire building, then you will need to involve more people, like the facility manager.
This article will provide you with further explanation about developing a plan:
These materials will also help you regarding developing a plan:
... ... ticle will provide you a further explanation:
- How to handle incidents according to ISO 27001 A.16 https://advisera.com/27001academy/blog/2015/10/26/how-to-handle-incidents-according-to-iso-27001-a-16/
- Incidents in ISO 22301 vs. ISO 27001 vs. ISO 20000 vs. ISO 28003 https://advisera.com/27001academy/blog/2016/09/05/incidents-in-iso22301-vs-iso27001-vs-iso-20000-vs-iso28003/
Â