Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • The CISO


    Answer:
    Regarding the definition of roles and responsibilities, there are some common roles that are established in companies with ISO 27001, the most common is the CISO. This article can be useful for you “What is the job of Chief Information Security Officer (CISO) in ISO 27001?” : https://advisera.com/27001academy/knowledgebase/what-is-the-job-of-chief-information-security-officer-ciso-in-iso-27001/

    Regarding the clause A.7.1.2 Terms and conditions of employment, simply each employee must have an agreement with the organization where all conditions are established. This agreement can also include information about the roles and responsibilities related to the ISMS (for example can be good for the agreement of the CISO).

    Regarding the clause A.13.2.4 Confidentiality or non-disclosure agreements, it is only necessary for information transfer (you need to establish an agreement with the other party for the information transfer, including terms rel ated to the information security), and it can be applicable to external parties or employees, but it is not directly related to the definition of roles and responsibilities.

    Finally, our course can be also interesting for you because we give more information about roles and responsibilities “ISO 27001:2013 Foundations Course” : https://advisera.com/training/iso-27001-foundations-course/
  • Corrective actions


    Answer:
    Regarding the first question, yes, it is necessary, because in accordance with the point 10.1 you need to eliminate the causes of a nonconformity, so if a nonconformity has been detected during an internal audit, you need to define corrective actions, and in the corrective actions you need to identify the causes of the nonconformity.

    Regarding the second question, KPIs are not mandatory in ISO 27001:2013, so there is no clause directly related to KPIs in ISO 27001:2013, although in accordance with the clause 9.1 you need to establish a way to measure the ISMS, and a KPI can help you (but it is not only the unique way). This article can be interesting for you “How to perform monitoring and measurement in ISO 27001” : https://advisera.com/27001academy/blog/2015/06/08/how-to-perform-monitoring-and-measurement-in-iso-27001/

    And our online course can be also interesting for you, because we give more information about the measurement of an ISMS “ISO 27001:2013 Foundations Course” : https://advisera.com/training/iso-27001-foundations-course/
  • IT audits and CISO


    Answer:
    I am not sure if I have understood 100% your question, but the CISO (Chief Information Security Officer) generally performs activities related to the implementation and maintenance of the ISO 27001 standard, and these activities should be reviewed during the ISO 27001 internal audit.

    But if your question is about IT audits (ethical hacking, penetration testing, etc), from my point of view it is not necessary to review the work of the CISO, you simply need to review the configuration of systems, open ports, services running, etc.

    This article can be interesting for you “What is the job of Chief Information Security Office (CISO) in ISO 27001?” : https://advisera.com/27001academy/knowledgebase/what-is-the-job-of-chief-information-security-officer-ciso-in-iso-27001/

    Finally, our online course can be also interesting for you because we giv e more information about the internal audit “ISO 27001:2013 Internal Auditor Course” : https://advisera.com/training/iso-27001-internal-auditor-course/
  • Threats and vulnerabilities list


    Answer:
    Our list of threats/vulnerabilities is a complete list of most common threats/vulnerabilities that covers most relevant aspects, so you can use this list for your risk management methodology. Here is our list of threats/vulnerabilities “Catalogue of threats & vulnerabilities” : https://advisera.com/27001academy/knowledgebase/threats-vulnerabilities/

    By the way, if you want to develop your own methodology, this article can be also interesting for you “How to write ISO 27001 risk assessment methodology” : https://advisera.com/27001academy/knowledgebase/write-iso-27001-risk-assessment-methodology/

    Finally, our online course can be also very interesting for you because we give more information about the risk management “ISO 27001:2013 Foundations Course” : https://advisera.com/training/iso-27001-foundations-course/
  • Identifying risks


    Answer:

    When identifying risks you need first to think about the scope of risk identification. In terms of ISO 9001:2015, you need to consider risks and opportunities related to ability of the organization to achieve its objectives. This includes risk emerging from internal and external context of the organization. For more information, see: The Role of Risk Assessment in the QMS https://advisera.com/9001academy/blog/2014/01/07/role-risk-assessment-qms/

    Risk management include systematic approach to risk control. This includes defined process of risk identification, evaluation, treatment and reassessment. For more information, see: Methodology for ISO 9001 Risk Analysis https://advisera.com/9001academy/blog/2015/09/01/methodology-for-iso-9001-risk-analysis/
  • The best way to perform the internal audit


    Answer:
    The best way to perform the Internal Audit is using a checklist, so this article can help you to develop you own checklist for the internal audit “How to make an Internal Audit checklist for ISO 27001/ISO 22301” : https://advisera.com/27001academy/knowledgebase/how-to-make-an-internal-audit-checklist-for-iso-27001-iso-22301/

    By the way, you can develop this checklist in the SharePoint, so from my point of view can be very useful.

    Finally, our online course can be also useful for you, because we give more information about the internal audit “ISO 27001:2013 Internal Auditor Course” : https://advisera.com/training/iso-27001-internal-auditor-course/
  • Risk interviews and workshops


    Answer: These interviews are based on collecting all the information for the Risk assessment sheet - i.e. listing all the assets, vulnerabilities, threats, impact, likelihood, and risk owner. These materials will help you:
    - article ISO 27001 risk assessment: How to match assets, threats and vulnerabilities https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/
    - article How to assess consequences and likelihood in ISO 27001 risk analysis https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#assessment
    - webinar The basics of risk assessment and treatment according to ISO 27 001 https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/

    The other question is related to the training awareness for risk assessment to asset and risk owners - is there any material you have which can give examples or demonstrate what we need to cover in the training.

    Answer: You should organize a workshop and teach them how to perform the whole process themselves. The best would be to take one department as an example, and list all the assets/threats/vulnerabilities for that department, as well as related impacts/likelihoods - this is partially explained in my book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
  • Incident and Service Request Management vs, Incident Management Toolkit


    Answer:
    Incident and Service Request Process (https://advisera.com/20000academy/documentation/incident-and-service-request-management-process/ ) is just process description according to ISO 20000. On the other side, Incident Management Toolkit encompasses all you need for Incident management solely.
    So, if you need to ensure all relevant processes are implemented on your Service Desk - include Request Fulfillment process as well as Service Asset and Configuration Management process, Change Management process, Problem Management process, Event Management process, Service Desk function, IT Operations Management function, Technical Management function, Application Management function. In such way you will cover most of the operational issues. Rest of the processes - depends how do the service look like. Please check ITIL® Documentation Toolkit (https://advisera.com/20000academy/itil-documentation-toolkit) which includes all mentioned processes and functions.
  • Impact and likelihood values


    Answer:
    I am sorry but I am not sure what do you mean. Basically, threats and vulnerabilities can help you to calculate values for the impact and the likelihood, and with the impact (damage that a threat can cause to the organization) and the likelihood (likelihood that a threat can be materialized) you can calculate the risk.

    So, a common way to calculate the risk is giving values to the impact and the likelihood, although another way for the calculation of the risk is giving values to the impact, threats and vulnerabilities.

    The mitigation means that you have a risk treatment plan and you have implemented security controls to reduce the risks, and this implies that the impact or the likelihood have been reduce. So, generally after the mitigation the impact value or the likelihood value is reduced.

    Anyway, this ar ticle can be interesting for you “ISO 27001 risk assessment & treatment - 6 basic steps” : https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/

    And also this one “ISO 27001 risk assessment: How to match assets, threats and vulnerabilities” : https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/

    Finally, our online course can be also interesting for you because we give more information about the risk assessment “ISO 27001:2013 Foundations Course” : https://advisera.com/training/iso-27001-foundations-course/
  • Application risk assessment


    Answer:
    If you mean how to perform the risk assessment for a software, basically you need to perform the risk assessment in the same way that for another asset, identifying threats/vulnerabilities and calculating the risk considering the impact and the likelihood of the threats, but in the case of software, you need to identify threats/vulnerabilities specifically related to the software (for example, regarding threats: software errors, unauthorized use of software, malicious code, unauthorized installation of software, etc. and regarding vulnerabilities: complicated user interface, default passwords not changed, insufficiente software testing, etc.). Here you can see a catalogue of threats/vulnerabilities “Catalogue of threats & vulnerabilities” : https://advisera.com/27001academy/knowledgebase/threats-vulnerabilities/

    This article can be also useful for you “ISO 27001 risk assessment: How to match assets, threats and vulnerabilities” : https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/ cademy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/

    And also this one “How to write ISO 27001 risk assessment methodology” : https://advisera.com/27001academy/knowledgebase/write-iso-27001-risk-assessment-methodology/

    Finally, our online course can be also interesting for you because we give more information about the risk assessment “ISO 27001:2013 Foundations Course” : https://advisera.com/training/iso-27001-foundations-course/
Page 990-vs-13485 of 1130 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +