Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Is double option mandatory In Europe and if yes where I can see in what countries it is?
I assume you are referring to double option in consent forms for different purposes. Well, if your organization is under GDPR, whether is based in EU or processes EU individual’s personal data, you will need to comply with GDPR worldwide.
You can find more information in the following article:
What is the EU GDPR and why is it applicable to the whole world? https://advisera.com/eugdpracademy/knowledgebase/what-is-the-eu-gdpr-and-why-is-it-applicable-to-the-whole-world/
If you have a question about to which countries is GDPR applicable, then please use this article instead: Is the GDPR applicable to our company? https://advisera.com/eugdpracademy/knowledgebase/who-needs-to-be-gdpr-compliant-an-easy-explanation/
You can also consider enrolling in this free EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//
To fulfill a form is always and in all the countries obligated to add the checkbox for marketing activities?
Yes, unless the marketing activity is the main purpose of data processing. I.e. in a subscription form to be informed about promotions. The purpose of processing is clearly marketing, and the user is giving consent for it. On the contrary, if the user is purchasing anything on the website or requiring general information if you want to use email for marketing purposes, you need to add the checkbox, because the user must be aware of what are you going to do with his/her e-mail.
You can find more information here:
How does GDPR impact marketing activities? https://advisera.com/eugdpracademy/blog/2018/02/08/how-does-gdpr-impact-marketing-activities/
How does GDPR affect digital marketing? https://advisera.com/eugdpracademy/blog/2019/02/20/how-does-gdpr-affect-digital-marketing/
Email marketing in the era of GDPR – How to ensure compliance? https://advisera.com/eugdpracademy/blog/2019/05/27/gdpr-and-email-marketing-rules-for-compliant-campaigns/
Is consent needed? Six legal bases to process data according to GDPR: https://advisera.com/eugdpracademy/knowledgebase/is-consent-needed-six-legal-bases-to-process-data-according-to-gdpr/
First, let us consider the elements of an environmental performance report.
You can consider adapting based on these elements:
About the evaluation mechanisms consider developing a monitoring plan, a dashboard including each environmental indicator and the state of each action plan. Define monitoring and analysis responsibilities and frequency.
Please consider the following information:
That will depend from organization to organization.
For example, if you consider a small medium company with Human Resources basically doing office work, you can ask: How does an office interacts with the environment?
Another example might be the Human Resources of a corporation, or a company with multiple units. In this case you might add:
Another example is an organization where Human Resources is also responsible for general organizational behaviors such as:
I recommend doing this exercise, as a brainstorm, fill the remaining spaces:
Please consider these sources of information:
The consequences may vary depending on the type of the non-compliance, but broadly speaking, ISO 27001 related non-compliances can be related to:
Regarding non-compliances identified during ISO 27001 certification/surveillance audit, they can lead to problems with the certification process.
These articles will provide you a further explanation about the impacts of non-compliances:
These materials will also help you regarding the impacts of non-compliances:
The need for recertification/refresher courses is defined by the certification issuer (e.g., Hightrust Alliance, CISSP and ISACA for their certifications), and what normally happens regarding ISO Auditor certifications is that recertification/refresher courses are necessary only when there is a change in the related management system standard (e.g., ISO 9001, ISO 27001, ISO 14001, etc), or in the audit standard (ISO 19011), so people can keep the necessary competences for audit, and such changes do not occur annually (it takes at least 5 years for a standard to be reviewed).
ISO 27001 does not prescribe ways to implement controls, only the objective to be achieved. For guidance on implementing this control, you should consider ISO 27002, a supporting standard that provides guidelines for implementation of controls from ISO 27001 Annex A.
Common solutions to implement this control are:
This article will provide you a further explanation about the application of control A.11.1.4:
Please note that there is no need for a folder A.5 in the toolkit because the policies needed to fulfill the controls from section A.5 from ISO 27001 Annex A are included in all other folders that make part of the folder 08 Annex A. In short, controls from section A.5 are not documents by themselves, but refer to other documents (A.5.1.1), and practices to be performed on them (A.5.1.2).
Regarding controls from section A.6.1, please note that roles and responsibilities are defined in each policy and procedure, so there is no need for a specific document to cover control A.6.1.1.
According to our experience, the BYOD and Mobile Device and Telework policies are sufficient to cover the controls of section A.6.
Additionally, is important to understand that ISO 27001 does not require every applicable control to be a separate document. In some cases, you only need to make a brief description of how it is implemented, and you can do that in our SoA template, in the column "Implementation Method".
This article will provide you a further explanation about the Statement of Applicability:
ISO 27001 does not prescribe records to be generated while managing physical access, but common records you should consider are:
This way you cover the main steps of access management: the definition of access rights, when they are used and changed, and when they are reviewed.
This article will provide you a further explanation about physical security:
This material will also help you regarding physical security:
The most common criteria to be considered for segregation of duties of critical activities are:
Considering that, for example, the internal auditor/security tester should not be the same person as the service manager. The service manager defines and handles changes/incidents, while internal auditor/security tester verifies if these are effective. So, you should verify exactly which activities will be performed by each role to identify potential conflicts of interest.
For further information, see:
These materials will also help you regarding segregation of duties:
This depends on your career objectives:
- The ISO 27001 Internal Auditor certification recognizes people capable of ISMS against ISO 27001. This allows them to perform audits in their own organizations.
- The ISO 27001 Lead Auditor certification recognizes people who have competency on auditing an ISMS against ISO 27001 requirements and qualifies them to audit other organizations on behalf of a customer, or to start the process to become a certification auditor.
These articles will provide you a further explanation about personal certifications:
- What does ISO 27001 Lead Auditor training look like? https://advisera.com/27001academy/blog/2016/08/29/what-does-iso-27001-lead-auditor-training-look-like/
- ISO 27001 Internal Auditor training – Is it good for my career? https://advisera.com/27001academy/blog/2016/03/29/iso-27001-internal-auditor-training-is-it-good-for-my-career/
These materials will also help you regarding audit training:
- ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-guide/
- ISO 27001:2013 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/
- ISO 27001:2013 Lead Auditor Course https://advisera.com/training/iso-27001-lead-auditor-course/