Answer: This situation is related to the "drop down" function in Excel (defining the size of the list of options to show in the drop down list). To find alternatives to adjust the options in your vulnerability selection box, please type "drop down add item" in the search field of Tell Me What You Want To Do in your Excel Functions tab.
The quickest way to solve this situation for you is to include a new line in any part in the middle of the list of vulnerabilities and include your data. After doing that you can reclassify your list in alphabetical order to organize the list with no problem.
Dear/Sir
Hi
Thank you very much for your answering and trying to help me, but your answer still not yet enough up to my knowledge .
I went through your articles which covers only 3 standards out of 5 and understand the requirements of risk management for each standard, but the problem couldn't imagine the model of risk management process for all 5 standards together how looks like?, in another words how can we combine all of these risk requirements (5 standards) in one risk management process such as the one in ISO 31000?
I hope that you understand me now and did not disturb you or wast your your time
Thank you again and have a nice time
Kind regards
Nuri
Control mapping
Answer: Generally, people do not do something (e.g., map controls in risk treatment plan) either because they do not know that this should be done, or because they do not know how to do it. These would be your most probable causes, which can lead to the following root causes: in-existent or unclear risk assessment methodology, or a lack or inadequate training program.
Answer: NIST Cybersecurity Framework (NIST CSF) provides a policy framework for computer security, while ISO 27001 provides a framework for information protection. ISO 27001 uses a process approach and the PDCA cycle, while NIST CSF uses the approach Identify - Protect - Detect - Respond - Recover.
Since most information today flows in cyber environments, NIST CSF can be used to support many of the IT-related controls described in ISO 27001 Annex A. On the other hand, ISO 27001 management practices can help build, maintain and improve a cyber environment which relies on NIST CSF.
ISO 27001 Annex A controls mapping to products and solutions
Nonetheless, if you don't mind for me to ask, do you have a mapping for ISO 27001 (Annex A) to technical controls (such as all of the technical products and solutions); I think it is more on IT/IT Security/CyberSecurity technical controls.
Answer: Since technical implementation will depend on each organization's business and security requirements, the market of technical solutions changes very quickly, and combinations of technologies can result in different levels of security, building and maintaining such mapping is unpractical.
What I can orient you to do is identify first the main concepts your security solution needs, based on the recommendations of Annex A controls (these are not product/technology - oriented) and then contact you regular suppliers or the big players to see what they can offer you to cover you r needs. Regarding specific technologies, maybe you can find information on NIST Special Publications (https://csrc.nist.gov/publications/PubsSPs.html)
Answer: For a good project scope definition you should consider questions about:
- How many locations would be involved
- Which finalist processes should be covered by the ISMS
- How many people work on the processes, and if there are multiple shifts
- The expected time frame for implementing the ISMS
With this kind of information you can have an idea of the effort that will be needed for the project.
Well, in that case you shouldn't be evaluated according to performance of some other department. If there is some way of getting out from this situation is to conduct customer satisfaction survey in a way that provides exact and precise answer on what the client is really complaining and then to conduct a root cause analysis to determine what is causing the problem. This would help your department to demonstrate that it is not its fault
This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember you. We use this information in order to improve and customize your browsing experience and for analytics and metrics about our visitors both on this website and other media. To find out more about the cookies we use, see our Privacy Policy.
If you decline, your information won't be tracked when you visit this website. A single cookie will be used in your browser to remember your preference not to be tracked.