What to do about assets and risks that change after risk assessment
Thank you so much. I thought that was the right thing to do.
Controls implementation, SoA and audit
Answer: The auditor can accept certain controls stated in the SoA to be implemented after the certification if: (1) all the major risks are resolved before the certification, (2) in the Risk Treatment Plan it is clearly defined that those controls will be implemented at a later date, and (3) the risk owners have accepted the risks related to controls that will be implemented later.
Answer: Unfortunately we do not have a specific sample for banks, but in this following material you can find a series of vulnerabilities and threats you can identify as applicable to you scenario:
In the video tutorial that came with your toolkit you can see examples of how to fill out all the data for Risk assessment and Risk treatment, and adapt those examples with the relevant vulnerabilities and threats you found the the catalogue.
Qualification of Quality Management Representative
Does he/she need to be certified or not?
Answer:
In the 2015 version of the standard there is no longer a requirement for management representative, but even with the 2008 version of the standard there were no explicit requirements for the MR (management representative) qualification. Considering the roles and responsibilities that the MR, it is expected MR to be familiar with the requirements of the standard and the processes within the company, but there is no requirement for being certified although it can be upper hand for the candidate for MR.
Answer: First, thanks for buying our book. In it you will find very precise steps about where to start from and what to do, regarding either the ISO 27001 implementation project, choosing the certification body, and the certification process.
2 - Does it worth it to certificate my processes (hardware) ?
Answer: ISO 27001 certification considers a scope defined in terms of information, processes or organizational units, so you cannot certify hardware, but it will hardly be out of any type of scope you decide to define.
4 - What do you suggest to certify at first (server, processes, site)?
Answer: For small organizations (i.e., up to 100 e mployees), the best course of action is to consider certification of the whole company (site). For those that are bigger, certificating one department, or one location, to start from and after that increase the size of the scope as needed is a better option.
Do changes in top management require changes in the documentation?
Answer:
The documentation should reflect the current situation in the company, and the documents to be changes should be the ones directly related to the top management, e.g. Quality Policy. However, if the process procedures, policies, etc remain the same as they were before the change, there is no need to change them just to replace the name of the person who authorized them. The most important thing for each document is whether the approved version is on the place of application, not who approved the document.
For the documents you decide to change, you need to apply your procedure for document control. I assume that you procedure requires you to record the change in section "change of document", here you need to write what has changed and who made the change and when. Again, dependin g on the rules prescribed by your procedure for document control you need to perform withdrawal of obsoleted documents, the standard doesn't define how to do it so all you need to do is to follow your procedure.
The standard requires organization to determine interested parties and their needs and expectations relevant to the Quality Management System and to monitor information about these interested parties and their requirements. If you meet these requirements you are compliant with the standard, it is up to the company to decide to group the interested parties based on either their requirements, functions, importance or any other criteria that the company determines, there is no requirement to name the parties individually.
All these elements, if we talk about the objectives, are product of practice and it is a proven method for establishing and achieving the objectives. The information needed for evidence based decision making are required by the standard and again the standard is made according to best practices that ensure quality of the products and services and customer satisfaction.