Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... ISO 17025 vs. ISO 9001 – Main differences and similarities - https://advisera.com/17025academy/blog/2019/07/11/iso-17025-vs-iso-9001-main-differences-and-similarities//
Please check our ISO/IEC 17025 Blog - https://advisera.com/17025academy/blog/
Download free ISO/IEC 17025 materials - https://advisera.com/17025academy/free-downloads/
... -27001-lead-implementer-training-look-like/
- What does ISO 27001 Lead Auditor training look like? https://advisera.com/27001academy/blog/2016/08/29/what-does-iso-27001-lead-auditor-training-look-like/
- Lead Auditor Course vs. Lead Implementer Course – Which one to go for? https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
... onsultant vs. DIY approach https://info.advisera.com/27001academy/free-download/implementing-iso-27001-with-a-consultant-vs-diy-approach
These materials will also help you regarding ISO 27001 implementation:
2 - Is the initially defined scope practical in your expert opinion?
Answer: Separated scopes certified at different times is a good approach when you have limited resources and some business units, besides the head office, are more critical than others (you can certify them in the order more relevant to the business).
It is important to note that you do not need to certify other business units after the head office (if ISO 27001 certification is more urgent for business units you can start with them).
For further information regarding scope definition, see:
3 - Are your templates and services applicable to our company as it's designed for small and medium corporate?
Answer: It is true that our templates are designed for companies of up to 500 employees. Therefore, for organizations with more than 500 employees the templates will require you to add more text into some of the documents (e.g. into the Risk Assessment Methodology) to address higher complexity of the company of your size. We do have couple of larger clients who adapted the templates successfully.
... : Hazards vs. risks – What is the difference according to DIS/ISO 45001?, https://advisera.com/45001academy/blog/2016/03/23/hazards-vs-risks-what-is-the-difference-according-to-disiso-45001/
3. What is the importance of an evacuation policy, and how can it be developed?An evacuation policy is one of the emergency response plans to have in place that you create in response to a potential problem. It is often developed by identifying the potential problem to be controlled, then identifying the evacuation that is needed in response to this problem. For more on this topic see the article: 5 elements to consider when testing your organization’s health & safety emergency response procedure, https://advisera.com/45001academy/blog/2017/02/22/5-elements-to-consider-when-testing-your-organizations-health-safety-emergency-response-procedure/
... or Course vs. Lead Implementer Course – Which one to go for? https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
This material will also help you regarding ISO 27001 personnel certifications:
- ISO 27001 Lead Auditor Course preparation training [free webinar on demand] https://advisera.com/training/iso-27001-lead-auditor-course/
For courses related to these certifications, please see:
- ISO 27001:2013 Lead auditor course https://advisera.com/training/iso-27001-lead-auditor-course/
- ISO 27001:2013 Lead implementer course https://advisera.com/training/iso-27001-lead-implementer-course/
Unfortunately, we do not have this specific mapping available.
However, you can combine the information provided in ISO 13485 Annex B (which maps ISO 13485:2016 clauses to ISO 9001:2015 clauses) with the information provided in this free downloadable material to have a link between ISO 13485 and ISO 27001:
... or Course vs. Lead Implementer Course – Which one to go for? https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
This material will also help you regarding ISO 27001 personnel certifications:
- ISO 27001 Lead Auditor Course preparation training [free webinar on demand] https://advisera.com/training/iso-27001-lead-auditor-course/
For courses related to these certifications, please see:
- ISO 27001:2013 LEAD AUDITOR COURSE https://advisera.com/training/iso-27001-lead-auditor-course/
- ISO 27001:2013 LEAD IMPLEMENTER COURSE https://advisera.com/training/iso-27001-lead-implementer-course/
... ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
- ISO 27001 vs. ISO 27017 – Information security controls for cloud services https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
- ISO 27001 vs. ISO 27018 – Standard for protecting privacy in the cloud https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/
- Understanding IT disaster recovery according to ISO 27031 https://advisera.com/27001academy/blog/2015/09/21/understanding-it-disaster-recovery-according-to-iso-27031/
- ISO 27001 vs. ISO 27032 cybersecurity standard https://advisera.com/27001academy/blog/2015/08/25/iso-27001-vs-iso-27032-cybersecurity-standard/
2 - I was keen to understand about risk, does it make sense to just use the iso risk approach or methodology like the FAIR institute? Lost here in direction to study.
Answer: ISO 27001 does not prescribe which methodology to use for information security risk management, so you can use the approach it is best for your organization (e.g., FAIR, ISO 27005, ISO 31000, NIST RMF, etc.)
These articles will provide you a further explanation about risk management:
- How to address opportunities in ISO 27001 risk management using ISO 31000 https://advisera.com/27001academy/blog/2018/04/13/how-to-address-opportunities-in-iso-27001-risk-management-using-iso-31000/
- How to use the NIST SP800 series of standards for ISO 27001 implementation https://advisera.com/27001academy/blog/2016/05/02/how-to-use-the-nist-sp800-series-of-standards-for-iso-27001-implementation/
... rtunities vs. environmental aspects - https://advisera.com/14001academy/blog/2016/06/06/iso-14001-risks-and-opportunities-vs-environmental-aspects/
Free webinar - Free webinar - ISO 14001: Identification and evaluation of environmental aspects - https://advisera.com/14001academy/webinar/iso-14001-identification-and-evaluation-of-environmental-aspects-free-webinar-on-demand/
Enroll for free in this course – ISO 14001:2015 Foundations Course - https://advisera.com/training/iso-14001-internal-auditor-course/
Book – The ISO 14001:2015 Companion - https://advisera.com/books/the-iso-14001-2015-companion/
... ce visits vs. certification audits – https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-au