Hi All I have been asked to write up a project plan with a view to my company getting certification. Has anyone got any views on what should be included in it?...
Hi James, A basic plan should start around identifying the phases: Planning & Empowerment Assessment Development Implementation Certification Management The...
At work, I have been asked to implement ISO 20071 instead of 17799, I have no idea what to do and how should we start ? because I am totally new to this. ...
Hi, Based on that, it sounds like your organization is interested in making sure that your Information Security function is being managed effectively. There...
Hi, is it ISO 27001 or 20071????? If it is ISO 27001... then just chill... ur on track.... ISO 17799 is called as part 1 and ISO 27001:2005 is known as part 2...
I have no idea about this new standard mate. ISO 20071. Sounds exciting. Legal Disclaimer ========================================= No animal was harm in...
This reply was actually from: pargovind@... ... it was originally deleted in error. ... Hello, I take it that it was simply a typo when you said "ISO...
Dear All, I have been a quiet member of this group, and constantly reading all the messages. The kind of information flowing is very good! I need a small help...
Nagendra, Below is the explanation for fmost of the clauses... go thru them once and try to understand.. I think it is explained in a simple way so u should be...
Hi All, Are there any guidelines for auditing financial applications built inhouse? For one, I see that there is one person, acting as a system analyst, system...
Dear All, I am Rohan Kadam, an engineer by profession. Currently I am working with Financial BPO. I've comprehensive 5 years experience in Quality Management...
Dear Rohan, ... It can't be denied. Any scope you choose, let's say a web server is accreditable. ... You can choose any method you want, you can even make up...
Dear Rohan, Answers are given below the questions. Although, I feel an Implementation course would be the best option for you. Other members can correct me...
Dear Rohan, Statement of applicability is the last stage of implementation. If compliance is new to your organization, i would suggest to start from defining...
Hi Rohan...I see that quite a few people have already replied to your queries. Just want to throw some more light on the basic issues you face, as I feel they...
In looking at the paperwork for this it becomes clear that this is very much oriented toward an officious process centered around the UK. Nominations and...
I suspect they broke it up in parts to supply the vendor community with multiple "new" niche markets to pursue. ks C. Karen Stopford, CISSP AVP Information...
Dear Rohan, I would agree with Manish that you need some kind of formal training if you are the Lead for the project. Better to be well informed in this case....
HI All, Please clarify me the following query regarding the "Documented procedure for measurement of effectiveness of controls " . Basically Im not sure what...
Dear Sameer, ... Measured effectiveness measures what results are you getting in comparison with an ideal (baseline) I have said this before. My opinion is...
Dear friends, I am back with my other query. Please guide me on drafting Telephone/ Fax Policy for my organization. Points to be considered are Making...
Hi Gang, I am an IT project manager tasked with aligning our entrprise security with the ISO 27001:2005 and ISO 17799:2005 standards. We are not after ...
For anyone who hasn't seen it: THE ISO 27001 and ISO 17799 NEWSLETTER - EDITION 14 Welcome to the Issue 14 of the ISO27001/ISO17799 newsletter, designed to...
Dear Members, I am confused bit about BCP and DRP... can anyone help me that wats the big difference between these two Terms.. Waiting for your quick...
My view: Business Continuity Planning - planning for continuity of the business - includes things like officer replacement as they retire, continuity of...
BCP is the safeguards that you put in place so that your business can continue uninterrupted when something bad happens. Example: UPS and generator for...
A business continuity plan (BCP) is a management process to ensure the continuity of businesses. Not to be confused with continuity of operations (COOP) where...
Dear Suneel, Business continuity planning is the process and procedures that an organisation can put in place to ensure that essential business functions ...
Hi Suneel, Please go through the definitions that are self-explanatory. BUSINESS CONTINUITY PLANNING (BCP): An all encompassing, "umbrella" term covering both...
Dears, i'm working with the iso 27001, and a few days ago, i received an certification external audit. The auditor requested me a high level of details in the...