Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
These materials will also help you regarding controls from Annex A:
... ompliance-vs-iso-27001/" class="content-link Link" target="_blank">https://advisera.com/27001academy/blog/21/01/27/hipaa-compliance-vs-iso-27001/
- Comparison of SOC 2 and ISO 27001 certification https://advisera.com/27001academy/blog/21/02/02/iso-27001-vs-soc-2/
- Does ISO 27001 implementation satisfy EU GDPR requirements? https://advisera.com/27001academy/blog/2016/10/17/does-iso-27001-implementation-satisfy-eu-gdpr-requirements/
- PCI-DSS vs. ISO 27001 Part 1 – Similarities and Differences https://advisera.com/27001academy/knowledgebase/pci-dss/
In case you are interested in which legal requirements you need to consider when implementing ISO 27001, our recommendation is for you to hire a local legal expert to help you identify such requirements. An online search can help at the beginning of your work (for an overview), but local expert advice is highly recommended.
This article can provide a start: https://advisera.com/27001academy/knowledgebase/laws-regulations-information-security-business-continuity/
But please note that the list in this article is not fully up-to-date because it depends on voluntary contributions from our readers – therefore, it is likely that not all regulations for each country are listed (some even may have been withdrawn).
These materials will also help you regarding ISO 27001:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
The Auditor said: “Essentially, your Correction Plan is identical to the Corrective Action Plan", but it wasn't exactly the same, of course, it is similar.
... /iso-9001-vs-iso-13485/" class="content-link Link" rel="nofollow ugc">https://advisera.com/9001academy/blog/2015/01/21/iso-9001-vs-iso-13485/
... iso-27001-vs-soc-2/" class="content-link Link" target="_blank">https://advisera.com/27001academy/blog/21/02/02/iso-27001-vs-soc-2/
These materials will also help you regarding ISO 27001:
if I have to establish and develop ISO 13485 for a company predominantly is AI and software driven medical devices, what are the main differences between medical device vs the above mentioned medical device.
... ontroller vs. processor – What are the differences? https://advisera.com/eugdpracademy/knowledgebase/eu-gdpr-controller-vs-processor-what-are-the-differences/
If you need to understand how controllers need to comply with GDPR, you can consider enrolling in our free online training EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//
I see what appears to be a merge between hashtag#SOC2 and hashtag#iso27001 audit controls and offered as the "SOC2 plus ISO" audit. The challenge I see with most mappings for the audit is the omission of Clause 4-10.
Dejan Košutić do you see a "HIPAA plus ISO" being born and if so, how does Clause 4-10 apply?
...
This course can give you further information about internal audit: