SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Incidents and Non conformities

  Quote
Guest
Guest user Created:   Mar 02, 2017 Last commented:   Mar 02, 2017

Incidents and Non conformities

1 - Couple of employee are sharing the passwords among them and we have Password policy in place. what will you raise against them ? security incident or non conformance ?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 02, 2017

2 - Email exchange is down for sometime and there is no email service : major incident ? or security incident ? or problem ?

I would like to know when to raise them ? Even though it is mentioned : NC is non-fulfillment of a requirement and security incident an unwanted event which Happened and lead to a compromise of business

Answer: The main criteria you can use to identify what you can rise is the type of impact on business caused by the situation. And you also should note that these options do not exclude each other, so for a same situation you can rise a security incident, a non conformance, a major incident and a problem. Let's take a look at your examples:

In example 1 we have a policy not being followed, so you can raise a non conformity. To know if the situation is also a security incident, we have to know if this caused any impact on the business, e.g., sharing of passwords caused an important file to lose its integrity when users attempted to update it at the same time from different locations. If no impact was perceived, you raise only the non conformity.

In example 2, you definitely have a security incident, but you have to identify which is the impact to classify it as a major incident. How many people were affected by the service downtime? Which business processes were affected? For example, the downtime happening during a Saturday night may have less impact than other happening at 3 pm on a Thursday. Regarding the identification as a problem, you only can use this classification when you do not know the cause of the downtime, because this situation will lead you to an additional effort to also discover the root cause of the situation, so you can try to eliminate it.

This article will provide you further explanation about Incidents:
- Incidents in ISO 22301 vs. ISO 27001 vs. ISO 20000 vs. ISO 28003 https://advisera.com/27001academy/blog/2016/09/05/incidents-in-iso22301-vs-iso27001-vs-iso-20000-vs-iso28003/
- How to handle incidents according to ISO 27001 A.16 https://advisera.com/27001academy/blog/2015/10/26/how-to-handle-incidents-according-to-iso-27001-a-16/

These materials will also help you regarding Incidents and Non conformities:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 02, 2017

Mar 02, 2017

Suggested Topics