Guest
We have bought the toolkit (German version) and I have one question:
Which parts and elements are needed within the documentation and description of interfaces and dependencies from “outside” services in connection with the scope of the ISMS. We have identified several interfaces to parties which are not directly included in the scope of the ISMS. For example:
So what is needed to describe these interfaces?
Regarding 27001 Toolkit\08_Annex_A_Security_Controls\A.14_System_Acquisition_Development_and_Maintenance:
We do not do any software development. Is it safe to say that we do not need to complete this Policy and Appendix on Specification o Requirements? If so, do we note this elsewhere in the documentation?
I have a question regarding the policies and standards that will be customised. Is the template are mapped with NIST and CIS 20 requirements?
We have purchased your „ISO 27001 Power Toolkit" and would need support. We, ***, offer our customers a SaaS solution. We are currently preparing for TISAX certification and are in the process of setting up the ISMS. TISAX is largely based on ISO 27001.
Here is my question about the scope to be determined:
Our headquarters are in the *** with branches in various countries among others in ***. Only the branch based in *** should be certified and defined in the scope. The design and maintenance of the IaaS and SaaS is specified and executed by the *** headquarters, Therefore we want to treat this area (hosting) and thus its service lines as a supplier. The problem is that employees in our IT department in the *** branch take on maintenance and administrative tasks for the EMEA area of hosting. How can this be excluded in the definition of the scope?
One point that wasn’t answered is regarding underscores in a file name.
In terms of best practice and your opinion, given that all the document templates in your toolkit have underscores is this something you recommend? What is the reason for having underscores in the file name?
Can you help me with one question, please?
Which document/template is used for the context of the organisation in the ISO27001 toolkit?