One of the most useful CSA's resources is the Cloud Controls Matrix, currently on version 3.0.1. It is a mapping of CSA recommended practices to the most known standards and regulations regarding information protection. Considering ISO standards, this matrix maps CSA practices to:
So, if someone whishes to create a vendor assessment guideline alignend with CSA practices, he can use the Cloud Controls Matrix to identify which CSA recommendations are mapped to supplier management practices from ISO 27001 (items marked with A.15.x.x) and ISO 27002 (items marked with 15.x.x), and choose those that are best fit for his organization. He also can use the same method to align his guideline to ISO 27017 (s ecurity in cloud services) and ISO 27018 (protection of PII).
Policies are clear, simple statements of how your organisation intends to conduct its services, actions or business. They provide a set of guiding principles to help with decision making. Policies don't need to be long or complicated – a couple of sentences may be all you need for each policy area.
Procedures describe how each policy will be put into action in your organisation. Each procedure should outline:
- Who will do what
- What steps they need to take
- Which forms or documents to use.
Procedures might just be a few bullet points or instructions. Sometimes they work well as forms, checklists, instructions or flowcharts.
Policies and their accompanying procedures will vary b etween workplaces because they reflect the values, approaches and commitments of a specific organisation and its culture. But they share the same role in guiding your organisation.
In terms of ISO 9001 it is more common to write a procedure for HR, Biomedical Engineering, IT, Purchasing and Warehouses, and so forth because they fit better with the attributes of a procedure mentioned above.
Second, you might find some controls applicable even though there are no related risks: there are cases when you have to comply with some laws or regulations - e.g. applying encryption - even though the risk assessment does not show any related risks.
Answer:
Basically the asset value is the same that the impact value, and can be calculated as an assessment of impact of loss of confidentiality, integrity and availability of information.
I didn't know if I should have our quality manual follow the same format as the new ISO:2015. i.e have the following clause headings.
0) Introduction
1) Scope
2) Normality references
3) Terms and definitions
4) Context of organization
5) Leadership
6) Planning
7) Support
8) Operation
9) Performance evaluation
10) Improvement
Is it advisable though to update to reflect new versions of the ISO?
Answer:
There is no requirement for Quality Manual to follow structure of the standard. The reason why companies decide to do so is because it helps them see how each of the clauses are met in their Quality Management System. Other than this, there are no reasons for adopting the clause headings of the standard in the manual.
In order to evaluate risks you need to define criteria. Criteria can be based on one or several features. Usually the criteria for evaluation of risk is a severity or consequence of the risk, if the risk has big severity or consequence, it is ranked higher on the list of risks or it can be labeled as significant risk in opposition to insignificant risks with small severity or consequence.
Another feature that can be taken as a criteria for risk evaluation is frequency of occurrence or probability. Some risk can have a big consequence but it rarely happens, so such risk can be considered as insignificant or low on the list of priorities. The risk with high probability and big consequence should be considered as significant, or unacceptable and such risk should be addressed.
There are additional criteria for evaluation of risk, such as detection, that can be used but the number and type of criteria to be used will depend on the needs of the company. Smaller companies will use simpler criteria that can be qualitative or quantitative and bigger and more complex companies will use more criteria and qualitative methodology.
The most important thing about documentation in new version of the standard is that it refers to it as "documented information" and this term includes both documents and records. There are far less requirements for documentation in 2015 revision of the standard, there is no longer requirement for Quality Manual and six mandatory procedures as in 2008 revision.
In order to conduct the transition, you need to update your existing documents to adapt them to new requirements. Almost every requirement is altered to some extent and clause numbering is changed so every document will require at least minor updates. Also you will have to decide whether to keep the documents and procedures that are not mandatory any more, for example although the manual is no longer mandatory, lots of companies decide to keep it because they find it useful for their QMS.
Answer:
ISO 27001 is developed for the establishment of an Information Security Management System, which means that this standard is for the protection of the information, so, basically ISO 27001 gives you a framework to identify risks and treat them implementing security controls, many of them are directly related to IT (but not all). So, this standard is not specifically developed to perform an IT audit, but you can use their security controls, although in the Annex A of ISO 27001 you can find a brief description of 114 security controls, while in the ISO 27002 you can find the same security controls but with a guide about how to implement each control.
So, maybe you can use the Annex A of ISO 27001 to select a group of security controls that you want to audit (related to IT), and if you need more information about each control you can see ISO 27002.
This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember you. We use this information in order to improve and customize your browsing experience and for analytics and metrics about our visitors both on this website and other media. To find out more about the cookies we use, see our Privacy Policy.
If you decline, your information won't be tracked when you visit this website. A single cookie will be used in your browser to remember your preference not to be tracked.