Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
- PCI-DSS vs. ISO 27001 Part 1 â Similarities and Differences https://advisera.com/27001academy/knowledgebase/pci-dss/
... ISO 27001 vs. ISO 27002 https://advisera.com /27001academy/knowledgebase/iso-27001-vs-iso-27002/
These materials will also help you regarding security measures and guidelines:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
... ... ically supporting processes).
When defining and documenting processes you need to apply requirements from clause 4.4,1 for every process. To distinguish between process and procedure, the easiest way is the process is set of activities that result in certain outcome and the procedure is description on how the process is carried out. For more information, see: ISO 9001:2015 process vs. procedure â Some practical examples https://advisera.com/9001academy/blog/2016/01/19/iso-90012015-process-vs-procedure-some-practical-examples/
... ification vs Design Validation - https://advisera.com/9001academy/knowledgebase/iso9001-design-verification-vs-design-validation/
- The ISO 9001 Design Process Explained https://advisera.com /9001academy/blog/2013/11/05/iso-9001-design-process-explained/
- free online training ISO 9001:2015 Foundations Course â https://advisera.com/training/iso-9001-foundations-course/
... ISO 27001 vs. ISO 27017 â Information security controls for cloud services https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
These articles will provide you further explanation about handling suppliers:
- 6-step process for handling supplier security according to ISO 27001 https://advisera.com/27001academy/blog/2014/06/30/6-step-process-for-handling-supplier-security-according-to-iso-27001/
- Which security clauses to use for supplier agreements? https://advisera.com/27001academy/blog/2017/06/19/which-security-clauses-to-use-for-supplier-agreements/
... />
- CISA vs. ISO 27001 Lead Auditor certification https://advisera.com/27001academy/blog/2015/05/11/cisa-vs-iso-27001-lead-auditor-certification/
This material will also help you regarding ISO 27001 Lead Auditor:
- ISO 27001 Lead Auditor Course preparation train ing [free webinar on demand] https://advisera.com/training/iso-27001-lead-auditor-course/
... >
- Major vs. minor nonconformities in the certification audit https://advisera.com/27001academy/blog/2014/06/02/major-vs-minor-nonconformities-in-the-certification-audit/
These materials will also help you regarding internal audit:
- ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-guide/
- ISO 27001:2013 INTERNAL AUDITOR COURSE https://advisera.com/training/iso-27001-internal-auditor-course/
... collection of the personal data.
If these information are lacking my first choice would be to consider that the US based company is acting as a processor and since they are dealing with a EU based controller there is high chance that GDPR would be applicable for the processing activities involving EU citizens personal data.
See also this article: EU GDPR controller vs. processor â What are the differences? https://advisera.com/eugdpracademy/knowledgebase/eu-gdpr-controller-vs-processor-what-are-the-differences/