Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Do we need sales procedure?

    No matter that you for now do not have classic sales, giving the license to another company and having some communication with them is part of the sales process. The sales process is not just sales of the final product to the final users, but rather all communication that you have with the companies that use your service. 
    Therefore, you need the sales procedure, but it will be specific for you for the communication with the licensed company. 

  • Design and development of a service

    Yes, a new design file needs to be created for each version of the facility. 

  • Conformio - ISO 27001 Requirements

    The treatment of the listed risks needs to be defined manually by the user when filling in the wizard. The wizard will only point out where in the document the customization needs to be done.

    In this case, the customization needs to be done in section 3.4.

    It needs to be performed manually because each organization may have its own way to treat the same list of risks.

  • Questions about Scope of my ISMS ISO 27001:2013

    1. Should I write the exact listing of all the information assets covered?

    2. Should I write the exact list of the information provided?

    3. Should I write the exact list of applications / software covered?

    4. Should I write the exact list of the physical offices covered?

    5. Should I write the exact listing of the databases covered?

    6. Should I write the exact list of websites / mobile applications covered?

    7. If I want to include all the information assets of my organization is it sufficient to write: "The scope of the SGSI covers all the information assets of the Organization" or do I have to be explicit by detailing all the information assets?

    This answer applies to questions 1 to 7.

    The ISMS scope is normally defined in terms of general information (e.g., business information, customer information, R&D information, etc.), processes (SW development process, customer support process, sales process, etc.) or location (e.g., headquarters, an office, a building, etc.) to be protected, so you do not need to include assets in the definition of the ISMS scope.

    For further information, see:

    8. Do I have virtual machines on Microsoft Azure that run critical applications, should I specify that the scope only covers the applications installed on these virtual machines that are on Microsoft Azure? or should I also include the virtual machines and their contents?

    When dealing with cloud services, you need to include in the ISMS only the elements you are responsible for. The other elements can be left out of the scope.

    In this case, if you control the virtual machines (i.e., their maintenance and operation), then you need to include them in the ISMS. In case not, you only need to include the applications in the ISMS scope.

    For further information, see:

    9. We currently have corporate mail with GOOGLE, is mail a critical asset in our organization, should I also include it in its scope if a service provided by a third party? What considerations do you have in the writing in the link at the level of this service?

    In this case, since GOOGLE provides email as a service, you need to include in the ISMS scope only the email data.

    10. Currently we send our customers emails and massive newsletters that contain important business information, are these emails and newsletters sent through a provider's software, should I also include it in the scope of a service provided by a third party? What considerations do you have in the writing in the link at the level of this service?

    In the ISMS scope, you need to include the reference to the data, and mention that related services are provided by third parties.

  • Swiss Notified Bodies

    No, it means that you can sell all products. Class I must be in compliance with the MDR from May 2021. So, you have a very good client that follows everything necessary. 

  • Legal and contractual requirements question

    First is important to note that the article linked to the template is only a starting point (it is updated by contributions of our readers and may not be fully updated). Our recommendation is for you to seek local legal advice so they can help you identify other legal requirements you need to consider for your ISO 27001 implementation (e.g., local laws and regulations).

    ISO 27001 does not prescribe how long the list of Legal, Regulatory, and Contractual requirements must be. It is likely your list will be short since normally transportation companies are not security regulated, but they might have some privacy regulations that are applicable. 

    For further information, see:

    How to identify interested parties according to ISO 27001 and ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-identify-interested-parties-according-to-iso-27001-and-iso-22301/
    How to identify ISMS requirements of interested parties in ISO 27001 https://advisera.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/

  • Mapping of requirements categories to ISO 27001 controls

    1) There may be a requirement for some controls for the HR department. We would then choose something like ‘Human Resources Security’ from the dropdown list for the Area field, right?

    But my point is that there is no option for Human Resources Security available from the dropdown list for the Area field.

     So my initial question some time ago was, why is Human Resources not listed as an area? Is this an omission (a bug) or has this been left out deliberately? And if so, why is this left out when all other control categories are available from the area drop down list.

    Answer: The absence of a Human Resources Security area is a design decision because HR security controls are related to the following areas:
    Managing security with suppliers and partners: A.7.1.1, A.7.1.2, A.7.2.2

    Confidentiality obligations and non-disclosure agreements: A.7.1.2, A.7.3.1

    Handling security events, incidents, and data breaches: A.7.2.3

    Control A.7.2.1 is related to the Information Security Policy

    But you are right, we will add the HR area to make the Register more user friendly.

    2) I understand the reasoning behind mandatory safeguards, but my question about that was where do these requirements show up in the SoA? Or do they need to be added to the SoA manually?

    I do believe that the combination of allowing the selection of an area together with the ability to specify individual controls would be taking the best of both worlds. I have made this suggestion to Aleksandra as art of request 63693.

    Answer: When a requirement area is chosen in the Register of requirements, the related controls will be displayed automatically in the Statement of Applicability. There is no need for manual addition.

    In case of need, i.e., when you need to related a control to a specific requirement not automatically defined, you can edit the specific justification in the SoA and make the inclusion manually.

  • Corrective actions and nonconformities

    Nonconformities found in the internal audit only will become a problem in the external audit if they are not solved as planned (i.e., actions related to them are not performed or are delayed without proper justification), or if there is a recurrence of the same nonconformity (this may mean that the root causes were not eliminated). In case they are solved as planned and there are no recurrences they will not mean a problem in the external audit.  

    Please note that ISO 27001 does not require non-conformities in internal audits to be classified. Normally non-conformities are classified during surveillance/certification audits.

    For further information, see:

  • Rules on a laboratory notebook

    A laboratory can use any medium and format to record technical data as long as the technical information is captured at the time of the activity, it is controlled and retained. The information must be traceable to personnel, equipment and time of activity to meet ISO 17025 clause 7.5 requirements.

    For more information regarding Records, see the ISO 17025 toolkit document template: Document and Record Control Procedure at https://advisera.com/17025academy/documentation/document-and-record-control-procedure/ as well as Control of data and information management, see the ISO 17025 toolkit document template: Quality Assurance Procedure at https://advisera.com/17025academy/documentation/quality-assurance-procedure/

Page 78 of 1130 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +