Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... the ISO 17025 document template: Quality Manual at https://advisera.com/17025academy/documentation/quality-manual/
It is important to understand the intent behind the revision, to help you implement ISO 17025 effectively. Have a look at the article ISO/IEC 17025:2005 vs. ISO/IEC 17025:2017 revision: What has changed? at https://advisera.com/17025academy/blog/2019/11/13/iso-17025-2017-vs-iso-17025-2005-key-changes-infographic/
How can i be able to integrate the two standards? ISO 9001:2015 and ISO 22000:2018
...
You may also consider enrolling in this online EU GDPR Foundations Course:EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//
... ce visits vs. certification audits https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/
This material will also help you regarding selecting a certification body:
what is the difference between document control and document management?
... ISO 27001 vs. ISO 27017 – Information security controls for cloud services https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
2. I am also confused about Business Continuity. Does that need to be in or not? You have taken it out in the demo.
Business continuity is not necessary to be implemented if you want to be certified only against ISO 27001, so you can delete from the Project Plan elements related to ISO 22301.
What happens with the Project Plan template is that it was designed to be used to implement both standards, and can be customized to fulfill customer's needs. In the comments included in the template you can find which text must be excluded or adjusted if you are going to implement only ISO 27001.
3. There is no section in the Project Plan for training. Should this not be part of the Project Plan?
Training as a deliverable is defined in section 3.2 (Project results) in the form of the "Training and Awareness Plan", which defines how employees will be trained to execute planned tasks, and how they will be made aware of the importance of information security.
Training for the project team can be defined in section 3.5 (Main project risks) as a treatment in case you have a risk related to untrained personnel in the project team.
For further information, see:
4. Should there not be a section on the test audit date as well?
Please note that there is no "test audit" concept in ISO 27001. What you need to perform is a full internal audit on all mandatory requirements and in all applicable controls, and the definition of audit dates will be covered when filling in the "Procedure for Internal Audit" and its support Annex "Annual Internal Audit Program".
For further information, see:
These materials can also help you regarding internal audit:
5. It seems like the Project Plan is just about completing the documents and nothing else.
First is important to note that this is a common misunderstanding.
Please note that at this stage of the project, without the definition of the ISMS scope and policy, and the definition of the controls to be implemented, there are not many things to do than completing the documents, but once you have the Statement of Applicability and the Risk Treatment Plan you will have a greater level of detail on what needs to be implemented in terms of processes and technologies.
To have a detailed idea of activities involved in the implementation, I suggest you take a look at this free downloadable material: Project checklist for ISO 27001 implementation (MS Word) https://info.advisera.com/27001academy/free-download/project-checklist-for-iso-27001-implementation
This checklist can help you keep track of all steps during the ISO 27001 implementation project, starting with obtaining management support all the way through to certification audit.
Could you please let me know what is the difference between major and minor nonconformity?
Could you please provide any practice tests/incidences to rule out any nonconformity present in the scenario?
Please note that although connected, BIA and Risk Assessment are different processes, and this connection does not make obsolete ISO 22317:2015, which defines guidelines for business impact analysis. You can still use this standard to help develop a BIA approach.
This article will provide you a further explanation about BIA and risk assessment:
... uires an overview of the situation, and the IT Risk Framework involves a deeper knowledge of risk management steps, the gap analysis would be easier to perform for a beginner.
This article will provide you a further explanation about the gap analysis and risk assessment (although the article is about ISO 27001 the concepts also apply to ISO 22301):
... ce visits vs. certification audits https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/
These materials will also help you regarding preparing for an audit: