Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... sk owners vs. asset owners in ISO 27001:2013 https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
2. Do I have to include also the private phones of our employees (their mailbox is configured on it and an app for 2 factor authentication)
Answer: If the organization does allow employees to use their own devices to access information included in the ISMS scope, then these personal devices should be included in the risk assessment.
For more information, see: How to write an easy-to-use BYOD policy compliant with ISO 27001 https://advi sera.com/27001academy/blog/2015/09/07/how-to-write-an-easy-to-use-byod-policy-compliant-with-iso-27001/
3. Do I have to include also the private PC of laptop that they use at home to connect via VPN to an online workplace where the can work from home?
Answer: Like the previous answer, if the organization does allow employees to use their own devices to access information included in the ISMS scope, then these personal devices should be included in the risk assessment.
For more information, see:How to apply information security controls in teleworking according to ISO 27001 https://advisera.com/27001academy/blog/2021/10/27/how-to-use-iso-27001-to-secure-data-when-working-remotely/
... nswer:
For an organization to become able to audit ISO standards it has to be compliant with ISO 17021 (the standard for organizations which want to get accredited for certifying management systems) recognized by the accreditation body of the country in which it wants to work
This article will provide you further explanation about accreditation:
- Accreditation vs. certification vs. registration in the ISO world https://advisera.com/articles/accreditation-vs-certification-vs-registration-in-the-iso-world/
... >
- Major vs. minor nonconformitie s in the certification audit https://advisera.com/27001academy/blog/2014/06/02/major-vs-minor-nonconformities-in-the-certification-audit/
3) What are, among the documented mandated information, those that really allow to demonstrate full awareness of the importance of adopting ISO 27001 best practices?
Answer: The main documents that give awareness of the importance of adopting ISO 27001 best practices are the Information security policy and objectives (covering clauses 5.2 and 6.2) and the Records of training, skills, experience and qualifications (covering clause 7.2).
These article will provide you further explanation:
- What should you write in your Information Security Policy according to ISO 27001? https://advisera.com/27001academy/blog/2016/05/30/what-should-you-write-in-your-information-security-policy-according-to-iso-27001/
- 8 Security Practices to Use in Your Employee Training and Awareness Program https://advisera.com/27001academy/blog/2015/03/02/8-security-practices-to-use-in-your-employee-training-and-awareness-program/
... p>... only one time, and after that you have a continuous maintenance effort, the demand for auditors is greater than for implementers. Also, to work for certification bodies is necessary to be approved in a Lead Auditor course, while for implementation the certification is not mandatory.
This article will provide you further explanation about these courses:
- Lead Auditor Course vs. Lead Implementer Course â Which one to go for? https://advisera.com/27001academy/blog/2014/06/16/lead-auditor-course-vs-lead-implementer-course-which-one-to-go-for/
... r persons vs. organizations https://advisera.com/27001academy/knowledgebase/iso-27001-certification-for-persons-vs-organizations/ 2. What is the process to getting certification once audits are complete? Answer: To have an overview of the ISMS implementation and certification process, please see these materials: - ISO 27001 implementation checklist https://advis era.com/27001academy/knowledgebase/iso-27001-implementation-checklist/ - ISO 27001: An overview of the ISMS implementation process [free webinar on demand] https://advisera.com/27001academy/webinar/iso-27001-overview-isms-implementation-process-free-webinar-demand/ - ISO 27001/ISO 22301: The certification process [free webinar] https://advisera.com/27001academy/webinar/iso-27001iso-22301-certification-process-free-webinar-demand/ - Becoming ISO 27001 certified â How to prepare for certification audit https://advisera.com/27001academy/iso-27001-certification/