Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... ... rence to ISO 27002.
Please note that ISO 27001 is the main standard for Information Security Management Systems, while ISO 27002 is a supporting standard that can be used to help implement controls from ISO 27001 Annex A.Â
Additionally, in certification audits, the auditor reference is ISO 27001, not ISO 27002.
For further information, see:
... ion/policy-for-data-privacy-in-the-cloud/
This document is based on guidelines from ISO 27018, a supporting standard to ISO 27001 which covers the protection of privacy in cloud environments.
For further information, see:
Please note that organizations can still certify against ISO 27002:2013 until October 31, 2023, and companies already ISO 27001:2013 certified still have until October 31, 2025, to make the transition to ISO 27001:2022.
For further information, see:
I am curious to get some input in regards to how you manage Suppliers of critical systems. At the moment I am struggling with deciding wheater we should consider all providers of citical systems also as a critical supplier and handle them in our supplier handling process. All critical systems are handled, risk assessed etc. according to our Asset management process. But I now ask myself if it is neccessary to also have all of them inserted as critical supplier and go through all the administrative work related to that.
example: we use Hubspot and this has been evaluated as a critical system. It is included in our system asset register, has gone though a comprehensive system review and we have the relevant contracts/agreements in the contract database. Would you also add Hubspot in the supplier register as a critical supplier? Which means that we will also evaluate the supplier on a regular basis etc.
Another aspect to this is that for systems that we "purchase" via a supplier.. then we don't have the actual provider of the system registered as a supplier but the partner that the system provider is using.
I would love to hear your thughts on this.
... analysis vs. risk assessment https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#section20
2. if so – do we have to implement all technical and organizational controls before we start the certification process? Or I it sufficient that we proof we are in control of the risks by following the ISO27001 ISMS norm?
It is sufficient to demonstrate that implemented controls are based on the results of risk assessment and applicable legal requirements as prescribed by the standard.
Please note that you only need to implement controls to treat relevant risks (based on the results of risk assessment) or to fulfill legal requirements (e.g., applicable laws, regulations, or contracts), so you do not have to implement all technical and organizational controls before we start the certification process.
This article will provide you with further explanation:
Hello, we purchased the ISO13485 kit from you guys and I have a question.. We have a QMS for our NIOSH/21CFR-820 doing some research the QMS requirements are very similar, the ISO13485 is more company operations and the NIOSH/21CFR-820 is both operations and product. Since we already have the NIOSH/21CFR-820 can we use this QMS for ISO13485?
... cuenta que se utiliza un análisis de brechas para evaluar su situación actual con respecto a los requisitos de ISO 27001, por lo que puede usarlo ahora mismo. En este momento, el análisis de brechas le dará una idea del esfuerzo para implementar el estándar.
Para obtener más información, consulte:
... better to perform the risk assessment during the implementation).
Please note that a gap analysis is used for you to assess your current situation regarding ISO 27001 requirements, so you can use it right now. At this time the gap analysis will give you an understanding of the effort to implement the standard.
For further information, see:
... ISO 17025 vs. ISO 9001 – Main differences and similarities at https://advisera.com/17025academy/blog/2019/07/11/iso-17025-vs-iso-9001-main-differences-and-similarities/
What is ISO 17025? at https://advisera.com/17025academy/what-is-iso-17025/ and the white paper
Clause-by-clause explanation of ISO 17025:2017 available at https://info.advisera.com/17025academy/free-download/clause-by-clause-explanation-of-iso-17025
... 7001 2013 vs. 2022 revision – What has changed? https://advisera.com/27001academy/blog/2022/02/09/iso-27001-iso-27002/
This material can help you: