Answer:
IT Operations Management function consist of two sub-functions: IT Operations Control and Facility Management:
- IT Operations Control - responsible for Execution and Monitoring of operative activities and Events
- Facility Management - Management of physical IT Environment
2 - Información sobre comó convertirme en Auditor Interno ISO 27001 (Information on becoming an Internal Auditor ISO 27001)
Answer: To get information about how to become an ISO 27001 internal auditor I suggest you these material:
- ISO 27001:2013 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/
- Qualifications for an ISO 27001 Internal Auditor https://advisera .com/27001academy/blog/2015/03/30/qualifications-for-an-iso-27001-internal-auditor/
Answer: In a MS interview generally they don't question technical things (e.g., what is ISO 27001, how it is implemented, etc.). At this point the interviewer is more interested in knowing your professional background, personal interests and why you are interested in the particular field of study you are pursuing. When this point arises, you can explain what would be your approach regarding the use of ISO 27001 in supporting organizations to be compliant with Cyber Law and protect information security.
What to do about assets and risks that change after risk assessment
Thank you so much. I thought that was the right thing to do.
Controls implementation, SoA and audit
Answer: The auditor can accept certain controls stated in the SoA to be implemented after the certification if: (1) all the major risks are resolved before the certification, (2) in the Risk Treatment Plan it is clearly defined that those controls will be implemented at a later date, and (3) the risk owners have accepted the risks related to controls that will be implemented later.
Answer: Unfortunately we do not have a specific sample for banks, but in this following material you can find a series of vulnerabilities and threats you can identify as applicable to you scenario:
In the video tutorial that came with your toolkit you can see examples of how to fill out all the data for Risk assessment and Risk treatment, and adapt those examples with the relevant vulnerabilities and threats you found the the catalogue.
Qualification of Quality Management Representative
Does he/she need to be certified or not?
Answer:
In the 2015 version of the standard there is no longer a requirement for management representative, but even with the 2008 version of the standard there were no explicit requirements for the MR (management representative) qualification. Considering the roles and responsibilities that the MR, it is expected MR to be familiar with the requirements of the standard and the processes within the company, but there is no requirement for being certified although it can be upper hand for the candidate for MR.
Answer: First, thanks for buying our book. In it you will find very precise steps about where to start from and what to do, regarding either the ISO 27001 implementation project, choosing the certification body, and the certification process.
2 - Does it worth it to certificate my processes (hardware) ?
Answer: ISO 27001 certification considers a scope defined in terms of information, processes or organizational units, so you cannot certify hardware, but it will hardly be out of any type of scope you decide to define.
4 - What do you suggest to certify at first (server, processes, site)?
Answer: For small organizations (i.e., up to 100 e mployees), the best course of action is to consider certification of the whole company (site). For those that are bigger, certificating one department, or one location, to start from and after that increase the size of the scope as needed is a better option.
Do changes in top management require changes in the documentation?
Answer:
The documentation should reflect the current situation in the company, and the documents to be changes should be the ones directly related to the top management, e.g. Quality Policy. However, if the process procedures, policies, etc remain the same as they were before the change, there is no need to change them just to replace the name of the person who authorized them. The most important thing for each document is whether the approved version is on the place of application, not who approved the document.
For the documents you decide to change, you need to apply your procedure for document control. I assume that you procedure requires you to record the change in section "change of document", here you need to write what has changed and who made the change and when. Again, dependin g on the rules prescribed by your procedure for document control you need to perform withdrawal of obsoleted documents, the standard doesn't define how to do it so all you need to do is to follow your procedure.