Search the web
Sign In
New User? Sign Up
iso-27001 · ISO 27001
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Hear how Yahoo! Groups has changed the lives of others. Take me there.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 115 - 144 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
115
Dear Friends, Our external auditors have put an observation that our ISMS Objectives need to be re-defined to be SMART, as presently they are too generalistic....
Sarat Kurra
saisaratk
Offline Send Email
Sep 15, 2006
7:32 pm
116
Dear Sarat, ... I think you will need ISM3 (www.ism3.com) to enhance your ISO27001 ISMS. ... A security objectices / security targets example from ISM3 is: ...
Vicente Aceituno
aceituno
Offline Send Email
Sep 18, 2006
11:31 am
117
refrence to your query, the opinion is as below: S - Specific--- means is to identify the key/target area for implemenatation of ISO M - Measurable----means is...
rana happy
avithakur2000
Offline Send Email
Sep 18, 2006
11:37 am
118
The latest issue has just arrived. For anyone who doesn't receive it, the full copy is below: ______________________________________________________ THE ISO...
iso17799standard
iso17799stan...
Offline Send Email
Sep 26, 2006
10:31 pm
119
Hi all I work for a commercial company and the head of Info Sec is an ex- military man. The company wants to achieve certification in the standard. Most of the...
BDSM Spank
triathlonman...
Offline Send Email
Oct 13, 2006
7:32 am
120
Hi JP, It's a common dillema. The head of Info Sec must understand that there are no mandatory controls. However, there are baselines. I suggest that you...
Rainier Vergara
rainvergara
Offline Send Email
Oct 13, 2006
8:34 pm
121
Hi, I'm an ISO 27001:2005 certified LA and LI ....Well if you ask me, there is a need to conduct Risk Assessment before since it will throw out the gap between...
Dhananjaya Naronikar
djisms
Offline Send Email
Oct 13, 2006
8:41 pm
122
Hi, Having done eight implementations for clients, both are right and otherwise. My experience with Auditors have been is that they are very cautious about the...
Mayank Bhardwaj
decaharry
Offline Send Email
Oct 14, 2006
8:15 pm
123
Hi, A week ago, I finished my eight implementation; whichwas certified. So far, I have conducted more than a dozen implementation courses; on behalf of BSI...
Mayank Bhardwaj
decaharry
Offline Send Email
Oct 14, 2006
8:23 pm
124
Hi JP, I think in corporate we are all working in a commercial concern. Anyway, if you look at the methodology of ISMS or ISO 27001,the methodology is -...
saisaratk
Offline Send Email
Oct 16, 2006
8:16 am
125
I'm in complete agreement with Dhananjay. It make sense to understand the applicability of Control Objectives before in order to ensure that Objectives are...
Raj
raj2610
Offline Send Email
Oct 16, 2006
8:20 am
126
Hello all, Recently I've been told by BSI representative that asset inventory prepared according to 4.2.1 d) clause of 27001 SHOULD include security...
Maxim S. Emm
maxus@...
Send Email
Oct 18, 2006
7:58 am
127
Hi Maxim, Good day. Even though your school of thought is worth thinking about.... in reality it is not that way. I do understand that the Security controls,...
Dhananjaya Naronikar
djisms
Offline Send Email
Oct 18, 2006
9:15 pm
128
Hi Maxim, The interpretation of the Asset Inventory to include firewalls etc is to ensure that during the risk analysis, these assets will reduce the risk to ...
Mayank Bhardwaj
decaharry
Offline Send Email
Oct 19, 2006
6:59 am
129
Hi, I think what has been recommened is correct but not the interpretation. Taking example of Firewall: If you do not include firewall as Information asset...
Paras Shah
paras181176
Offline Send Email
Oct 19, 2006
6:59 am
130
Dear Mayank, Are the one who conducted ISMS LA course during last Dec in Kol. If you the one pl send your mobile no.so that I can contact you. Regards Rupam...
rupam baruah
rupam_baruah
Offline Send Email
Oct 19, 2006
5:01 pm
131
Hi, I am working as the 'General Manager' of a Software firm which started 2 and half years back . We are a team of 34 Employees with 26 Technical people. We...
Rajesh Mathachan
rajmats
Offline Send Email
Oct 19, 2006
5:05 pm
132
Hi, Since you are at CMM Level 3 (IS it CMM or CMM(I)), would recommend you go for ISO 9001 first which should be a piece of cake. Then you can go for ISO...
abhi_ssa
Offline Send Email
Oct 19, 2006
7:47 pm
133
Hi , We are not CMM Certified , we follow CMM standards since we know the process (in personal level). I would like to know which is the best certification...
Rajesh Mathachan
rajmats
Offline Send Email
Oct 20, 2006
7:43 am
134
Hi Rajesh, I would suggest that you go for either IT Infrastructure Library (ITIL) and/or ISO 20000-1 IT Service Management System. It can enhance your service...
Rainier Vergara
rainvergara
Offline Send Email
Oct 20, 2006
7:45 am
135
Hi Rajesh, I woul go with Rain... First achive ITIL certification and then move on to ISO 27001:2005 certification since that would add considerable value to...
Dhananjaya Naronikar
djisms
Offline Send Email
Oct 20, 2006
6:06 pm
136
Hi Rajesh, As most of them know that for CMM an 'Assessment' is done on the processes, its upto you whether you want to follow after the assessments. But in...
nisumadi1 111
nisumadi1
Offline Send Email
Oct 20, 2006
6:08 pm
137
Hello Rajesh, I have read through the recommendations given out by other learned members in this group. Each of them have their own point and they require to...
pargovind
Offline Send Email
Oct 22, 2006
8:03 pm
138
Hi Rajesh Adding to Govinf comments, ... I agree. In between doing ISO9001 and ISO27001, you can use ISM3 (www.ism3.com). ISM3 has 5 maturity levels, and ...
Vicente Aceituno
aceituno
Offline Send Email
Oct 23, 2006
7:21 am
139
Hi, Is there any way or methodology by which I can synchronize Operational risk assessment and the Information Security Risk assessment, if we consider...
Arindam.Banerjee
Arindam.Banerjee@...
Send Email
Oct 23, 2006
3:30 pm
140
Well put Govind. I would like to pose a question- why do you want ANY certification? Your organisation is at CMM level 3. If I were you, I'd prefer to go to ...
Mayank Bhardwaj
decaharry
Offline Send Email
Oct 23, 2006
3:32 pm
141
Hi Mayank, Well, Rajesh's query was about which certification his organization could opt for. Obviously, the whole thread of discussion converges on ...
pargovind
Offline Send Email
Oct 23, 2006
6:41 pm
142
... I'd like to see some specific examples of that...I read ISO27001 back to back and I haven't seen any reference to specific legislation. ... I don't think...
Vicente Aceituno
aceituno
Offline Send Email
Oct 24, 2006
7:47 am
143
I think Rajesh has, by now, a good lot of ideas to mull over and take the right course that he deems fit. Well, people like Rajesh give practitioners a chance...
pargovind
Offline Send Email
Oct 24, 2006
8:07 pm
144
Hi, I had an opportunity to lead a very large effort in a US based multilateral Bank in implementing CMM, ITIL/ISO20000 and BS7799/IOSO27001 simultaneously...
csksekar
Offline Send Email
Oct 25, 2006
7:48 am
Messages 115 - 144 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help