You just need to scroll down the screen a little to find the free demo tab.
Customer requirements review
Answer:
Depending on the type of product or service you are providing to your customer you can get information on customer requirements in different ways. Sometimes, you can send your customer questionnaire or some other record that will provide you with sufficient information on customer requirements so you can decide whether you can meet these requirements or not. Or you can have a conversation with your customer and record its requirements by yourself.
The purpose of implementation of metrics in quality management system is to determine performance of the QMS. In order to achieve that, you need to define KPIs (Key Performance Indicators) for every process. KPIs should be defined in a way that provides you with information whether the process is delivering the expected outcome or some improvements are needed for the process.
Answer: You can understand context of organization as any internal or external factor that can affect the ISMS. As examples of external factors (something that is outside the organization's control) we can mention new technologies, competitors, and laws. As examples of internal factors (something the organization can control or have influence over) are organization's own resources and knowledge, its culture, and its employees competences. Understanding the context is essential to identify where the ISMS can be applied, its strengths and limitations.
1 - The format of the entire 27001 Standard. Do you have a sample format of what would need be presented to the external auditor please, ie. all the documents please?
This list of questions cover areas like knowledge of industry, use of methodologies and payment conditions you can use to evaluate potential candidates.
This material will also help you regarding selection of auditors and certification bodies:
Answer: If you are referring to our ISO 27001 foundation course, there is no need to buy additional material to take the exam. The information presented in the course will be sufficient to take the exam. But if you are considering another exam, or still consider acquiring more information before taking our exam, I suggest you to take a look at our book Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
This book contains an easy to follow structure for you to comprehend the ISO 27001 standard and implement it in an organization.
Obsolete equipment disposal
Answer: The most common difficulties regarding the proper disposal of obsolete equipment are:
1) make people aware of the importance of proper equipment disposal;
2) the need for space and access controls to store the equipment before they undergo the information sanitization procedures;
3) the control of information to ensure that no sensitive data is lost because users forgot to retrieve them from the equipment before sending them for disposal;
4) the disposal of equipment under BYOD terms.
Could you please let me know what type of document I should deliver to auditors? whether it is checklist which compare ISO27001 control with our policy or any other type of document?
Answer: I will assume that even though your organization is not ISO 27001 certified it considers relevant to follow its practices. Considering this, since ISO 27001 was updated on 2013, and organizational practices are based on 2005 version, your organization should present:
1) a management decision considering if it is still relevant to be aligned to ISO 27001 practices after the standard's update (this can be part of management review content)
2) if management has decided to maintain alignment, you also should provide a gap analysis between the organization's practices and the 2013 version o f ISO 27001, the management decision about how to proceed considering the gap analysis findings (e.g., what practices to update, what to keep and what to discontinue), and the action plans regarding the changes deemed relevant.
Answer: CISA is a certification issued by ISACA for persons who fulfills pre requisites related to audit of information systems, while ISO 27001 is a certifiable standard applicable to organization's Information Security Management Systems, but which also has a certification to recognize people capable to audit ISMS's compliant with this standard.
2 - if I have certificate of ISO27001LA and COBIT can it dispens of CISA.
Answer: This will depend of the type and depth of the activities you will perform. If your activity focuses on information security management, ISO 27001 LA would be sufficient. If you want to go a little deeper also considering IT governance activities and technical process, COBIT can help enhance your skills. CISA knowledge would help you perform audits that go beyond the scope of information security, also considering the strategic relationships of the information systems and business objectives.
3 - Who can I use ISO 27001 to audit my company step by step.
Answer: Business Continuity Management and Information Security overlap each other in several points and as business needs for stable and always available information systems grow, the need for professionals who can understand, explain and plan solutions which integrates these two fields will also grow, providing great opportunities for competent people. For more information, please see: Where does information security fit into a company? https://advisera.com/27001academy/blog/2016/10/24/where-does-information-security-fit-into-a-company/
This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember you. We use this information in order to improve and customize your browsing experience and for analytics and metrics about our visitors both on this website and other media. To find out more about the cookies we use, see our Privacy Policy.
If you decline, your information won't be tracked when you visit this website. A single cookie will be used in your browser to remember your preference not to be tracked.