Answer: ISO 27001 clauses do not require from an organization to include address information in documentation, so this decision is up to the organization itself, if it considers relevant to the business, it is demanded by law or contractual clauses, or as a result of a risk assessment.
You just need to scroll down the screen a little to find the free demo tab.
Customer requirements review
Answer:
Depending on the type of product or service you are providing to your customer you can get information on customer requirements in different ways. Sometimes, you can send your customer questionnaire or some other record that will provide you with sufficient information on customer requirements so you can decide whether you can meet these requirements or not. Or you can have a conversation with your customer and record its requirements by yourself.
The purpose of implementation of metrics in quality management system is to determine performance of the QMS. In order to achieve that, you need to define KPIs (Key Performance Indicators) for every process. KPIs should be defined in a way that provides you with information whether the process is delivering the expected outcome or some improvements are needed for the process.
Answer: You can understand context of organization as any internal or external factor that can affect the ISMS. As examples of external factors (something that is outside the organization's control) we can mention new technologies, competitors, and laws. As examples of internal factors (something the organization can control or have influence over) are organization's own resources and knowledge, its culture, and its employees competences. Understanding the context is essential to identify where the ISMS can be applied, its strengths and limitations.
1 - The format of the entire 27001 Standard. Do you have a sample format of what would need be presented to the external auditor please, ie. all the documents please?
This list of questions cover areas like knowledge of industry, use of methodologies and payment conditions you can use to evaluate potential candidates.
This material will also help you regarding selection of auditors and certification bodies:
Answer: If you are referring to our ISO 27001 foundation course, there is no need to buy additional material to take the exam. The information presented in the course will be sufficient to take the exam. But if you are considering another exam, or still consider acquiring more information before taking our exam, I suggest you to take a look at our book Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
This book contains an easy to follow structure for you to comprehend the ISO 27001 standard and implement it in an organization.
Obsolete equipment disposal
Answer: The most common difficulties regarding the proper disposal of obsolete equipment are:
1) make people aware of the importance of proper equipment disposal;
2) the need for space and access controls to store the equipment before they undergo the information sanitization procedures;
3) the control of information to ensure that no sensitive data is lost because users forgot to retrieve them from the equipment before sending them for disposal;
4) the disposal of equipment under BYOD terms.
Could you please let me know what type of document I should deliver to auditors? whether it is checklist which compare ISO27001 control with our policy or any other type of document?
Answer: I will assume that even though your organization is not ISO 27001 certified it considers relevant to follow its practices. Considering this, since ISO 27001 was updated on 2013, and organizational practices are based on 2005 version, your organization should present:
1) a management decision considering if it is still relevant to be aligned to ISO 27001 practices after the standard's update (this can be part of management review content)
2) if management has decided to maintain alignment, you also should provide a gap analysis between the organization's practices and the 2013 version o f ISO 27001, the management decision about how to proceed considering the gap analysis findings (e.g., what practices to update, what to keep and what to discontinue), and the action plans regarding the changes deemed relevant.