Search the web
Sign In
New User? Sign Up
iso-27001 · ISO 27001
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Hear how Yahoo! Groups has changed the lives of others. Take me there.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
ISO application to processes   Message List  
Reply | Forward Message #403 of 451 |
Does anyone know the potential pitfalls of applying ISO controls to processes?
My organisation is mooting an expansion of our registration to all of our top 40
applications (from 3) based on the approach of applying the 27001 controls to
the ITIL - type processes such as problem management, change and release, help
desk etc. It worries me slightly that if we fail in one process then this will
flow down into a failure across the board and it will appear that our security
has deteriorated. In actuality, it has improved in the past year.




Tue Jun 2, 2009 12:49 pm

nigelbeard98
Offline Offline
Send Email Send Email

Forward
Message #403 of 451 |
Expand Messages Author Sort by Date

Does anyone know the potential pitfalls of applying ISO controls to processes? My organisation is mooting an expansion of our registration to all of our top 40...
nigelbeard98
Offline Send Email
Jun 3, 2009
6:49 pm

Considering the client follows ISO 17799:2005 ISMS, when does the client define "Management responsibility"? a. standards are defined b. assets are identified ...
RiCkY
deepal.madlani
Offline Send Email
Jul 16, 2009
7:35 am

Hi, 2 cents from me - Clause 5 (Mandatory clauses) clearly explains that the Management Responsibility has to be set up before the start of implementation and...
Dhananjaya Naronikar
djisms
Offline Send Email
Jul 17, 2009
9:20 am

I appreciate your response. I am clear about the Clause 5. however, which is the best answer to choose from the options provided was my query. Thanks, Deepal ...
RiCkY
deepal.madlani
Offline Send Email
Jul 18, 2009
8:31 am

Duh? Why do you need to "define" management responsibility? ________________________________ From: RiCkY <madlaniricky@...> To: iso-27001@yahoogroups.com...
Eric Regalado
er_regalado
Offline Send Email
Jul 20, 2009
7:33 am

Eric, thats how the question was framed by the certification body :) ________________________________ From: Eric Regalado <er_regalado@...> To:...
RiCkY
deepal.madlani
Offline Send Email
Jul 21, 2009
7:43 am

... Hallo Deepal, ISO 27002:2005 (formerly known as ISO 17799:2005) is not necesseraly implemented starting at chapter 1 and ending at chapter 15, in that...
hwkeijzer
Offline Send Email
Jul 21, 2009
7:42 am

Dear all, I have few questions on control A11.7.2 implementation.  1. What is the normal trend on allowing users to work from home? 2.  Should they be...
balasaheb ware
balaware
Offline Send Email
Jul 18, 2009
8:31 am

Management responsibilities comes in cl 6.1.1 as management commitment. This is mandentory guidelines of ISO 17799:2005. It comes after policy documents are...
Bhavesh Pandey
bhavesh.pandey
Offline Send Email
Jul 18, 2009
8:31 am
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help