Answer: When there is a single person responsible for both, networks and applications, there is an increased risk that a malicious or unintentional misconfiguration leaves information exposed to unauthorized people.
For example, application servers sharing the same network with workstations makes infrastructure administration easier, but increases the risks of unauthorized access. Another example is an administrator that opens a service port in a server, and by configuring a network path, uses it for remotely access a server, when organizational policy prohibits that.
By segregating network and applications responsibilities it is more difficult for a single person to make such a mistake or intentional violation of access rights.
Answer: Risk reduction is an option where you take action to reduce the probability of an incident to occur (for example, by installing antivirus software you minimize chances of a computer to be infected) and/or the impact of an incident if it happens (e.g., by using backup, if by any reason you lose a file, the backup can be restored and recover part or all the information).
Risk sharing is an option when you decide either to transfer the operational management of the risk to a third party, or buy an insurance to minimize financial losses if an incident occurs. You should note that in case of risk sharing the final responsibility for the risk still remains with the organization.
Answer: The main purpose of Privacy Impact Assessments (PIA's) for EU GDPR is the identification of risks to the privacy rights of individuals when processing their personal data, so proper measures can be taken to properly protect them. In this context, risk assessments based on standards like ISO 31000, and most specifically ISO 27005, fits perfectly for this purpose. In fact, by simply implementing ISO 27001, complemented by ISO 27018, you will cover most of situations related to privacy risks.
Answer: Without relying on an IDS system, the best option to measure the probability of breach, or improvements on security by implementing new controls like 2 factor authentication, would be by performing periodic penetration tests and/or vulnerability assessments. They can provide an snapshot of your situation and help you manage potential risk.
References on Procedure for Document Control in Toolkit
Answer: The document control procedure, as well as many other documents in the ISO 27001 documentation toolkit, were developed to be compliant with both, information security management system and business continuity management system. That's why you will find references for these standards. If you did not implement the business continuity management system you can simply delete these references. Their deletion won't impact your ISMS.
Supply chain risks
Answer: The parameters used for vulnerability measuring on supply chain risks will be the same you use for measuring your own organizational risks (e.g., low, medium, and high).
What is different when you consider supply chain is that there will be new types of threats and vulnerabilities usually not found on internal operations (e.g., shared resources between tenants, contractual breaches, etc.)
Answer: No. The course was designed to help you understand ISO 27001 and manage risks using its content, but to do it properly you should attend all modules related to clauses 6 (planning), 8 (Operation) and Annex A, which would be modules 2, 3, 4, and 6. If you attend only module 3 you will miss items like Information security objectives [clause 6.2], and applicable controls [Annex A]
Answer:
There is no direct requirement (in ISO 20000) to audit the internal auditor, directly. If consider that internal audit is made before certification audit - that could be seen as a kind of audit of internal audit. But, explicit requirement doesn't exist.
Risk evaluation
>1 - Is this asset evaluation is mandatory in iso 27001.?
Answer: Risk assessment is a mandatory clause for ISO 27001, but you can choose which methodology to use, and assessing assets risks is just one of them. You can use, for example, scenario analysis, interviews or checklists also.
>2 - Can you please tell me what is the risk residual acceptance criteria .
Answer: The risk residual acceptance criteria are the same criteria you use to evaluate a risk. The difference is that they are applied to the risks after controls deemed necessary are implemented, so you can re-evaluate them to decide if additional treatment is necessary or if the risk as it is now will be accepted.
Becoming an ISO 27001 and information security expert
Answer: The path to become an ISO27001 and an Information Security Expert goes through acquiring theoretical and practical knowledge on information security and accumulation of experience solving daily problems.
So, you should consider buying documents like ISO 27001 standard (https://www.iso.org/isoiec-27001-information-security.html), attend courses about ISO 27001 and other related to information security, and apply those knowledges to implement security controls and solve daily situations like incidents.
Some organizations also measure an expert by the certification he holds, so you also should consider to include some certifications in your curriculum (e.g., ISO 271001 Lead Auditor, CISSP, etc.).
This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember you. We use this information in order to improve and customize your browsing experience and for analytics and metrics about our visitors both on this website and other media. To find out more about the cookies we use, see our Privacy Policy.
If you decline, your information won't be tracked when you visit this website. A single cookie will be used in your browser to remember your preference not to be tracked.