Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... 00-1:2011 vs. ISO 9001:2015 matrix”
- https://info.advisera.com/20000academy/free-download/iso-iec-20000-1-2011-vs-iso-9001-2015-matrix?_gl=1*ud8gcr*_ga*MTI5NjM5NjM3LjE2MjcyOTkzOTY.*_ga_4P5GYSBRB2*MTYzMTAwMDYyNi4zMS4xLjE2MzEwMDIwNTQuNjA. This document is being updated according to ISO/IEC 20000-1:2018
While considering the use of ISO 9001 for software development activities, consider this support ISO/IEC/IEEE 90003:2018 - Software engineering — Guidelines for the application of ISO 9001:2015 to computer software - https://www.iso.org/standard/74348.html
... sk owners vs. asset owners in ISO 27001:2013 https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
2 - Second one is regarding "justification" of adding particular control to SoA. I do not entirely understood how to read "justification" in this question?
Could you please explain it to me?
For SoA, “justification” is the reason for which a control is deemed applicable. The whole concept of ISO 27001 is that you only need to apply a control if you have a reason (i.e., a justification) for that. This ensures that you do not expend unnecessary resources and that all your requirements are properly covered.
For example, if you implement a cryptographic technology and you do not have a relevant risk to justify the implementation of control A.10.1.1 (Policy on the use of cryptographic controls), then you are expending resources unnecessarily (in an ISO 27001 point of view).
On the other hand, if you do not have relevant risks to justify the implementation of control A.10.1.1, but you have a contractual clause with a client stipulating the use of cryptography, then you need to include reference to this contractual clause to justify the use of the control.
... recovery vs Business continuity https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/
Question #2
Is chapter four of the business continuity recovery plan template sufficient against standard clause 8.4.5? Or should I supplement my recovery plans with additional steps?
I’m assuming you are referring to the Disaster Recovery Plan template.
In this case, the information to be included in the template is sufficient to be compliant with ISO 22301 clause 8.4.5.
For further information, see:
... rtunities vs. environmental aspects - https://advisera.com/14001academy/blog/2016/03/21/how-does-product-life-cycle-influence-environmental-aspects-according-to-iso-140012015/
... ontroller vs. processor – What are the differences? https://advisera.com/eugdpracademy/knowledgebase/eu-gdpr-controller-vs-processor-what-are-the-differences/ If you need how to implement EU GDPR, you may consider enrolling in our free EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course/
... ontroller vs. processor – What are the differences? https://advisera.com/eugdpracademy/knowledgebase/eu-gdpr-controller-vs-processor-what-are-the-differences/
If you need to understand how to comply with the EU GDPR you may consider enrolling in our EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course/
... authority to do something about it, in this case, the Accounting Director of company X. As for the person to perform risk assessment, you should consider the person with the most knowledge about the accounting program and related processes (in general this person is known as the key user).
This article will provide you a further explanation about risk owners:
... ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
- How to handle access control according to ISO 27001 https://advisera.com/27001academy/blog/2015/07/27/how-to-handle-access-control-according-to-iso-27001/