Search the web
Sign In
New User? Sign Up
iso-27001 · ISO 27001
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 177 - 206 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
177
Dears, i'm working with the iso 27001, and a few days ago, i received an certification external audit. The auditor requested me a high level of details in the...
fabianchiera
Offline Send Email
May 1, 2007
4:16 pm
178
... Yes it is. That's why ISO demands that you get things like policies approved by top management - and why they talk about the need for internal support for...
Fred Cohen
fcallnet
Offline Send Email
May 1, 2007
9:55 pm
179
Dear Fabian, I'm not sure if it is right answer what you are looking for. I thought that you should try with gap analysis using ISO 27001 comparing with being...
teerakrit
Offline Send Email
May 2, 2007
6:04 pm
180
Hi, If you are working on ISO 27001, then the standard scope is Information security (in all forms). It does not talk about identifying risk in new line of...
Bala Ramanan
balaramanan2000
Offline Send Email
May 3, 2007
6:58 am
181
Dear Fabin, Your RA shall assess the threat and vulnerabilities associated with the identified information, information processing & associated assets and...
Dinesh
dina_kd
Offline Send Email
May 4, 2007
7:26 am
182
Hi I would interpret the Auditors statement/requirement in a slightly different way. 1. All the busines function and the decisions they make in terms of...
Venu
venu_kailas
Offline Send Email
May 7, 2007
7:11 am
183
Dear All, I fully agree with Venu. I have seen many organisations where RA is done organisation wide and not at the process levels. Process owners should do ...
V Nagendra
vsnagi
Offline Send Email
May 7, 2007
9:16 pm
184
RA has to be done both at the org level & at the entitiy level within the organization. RA can be done by the process owners provided it is done in conjuction...
Raj
raj2610
Offline Send Email
May 8, 2007
2:46 pm
185
Dear All, I have been teaching a class on risk management recently and that got me thinking. I don't know if it happens to you, but I learn more when I teach...
Vicente Aceituno
aceituno
Offline Send Email
May 8, 2007
5:52 pm
186
Hi All, Vincente has really summed it up nicely. There is no single best way for RA. RA be done as per the Organisation's characteristics - SME, Large,...
Sarat Kurra
saisaratk
Offline Send Email
May 9, 2007
11:34 am
187
Hello, NIST - National institute of standards and technology has published "Risk Management Guide for Information Technology Systems". This is good RA...
Abhishek Maurya
abhi9211
Offline Send Email
May 9, 2007
3:09 pm
188
Hi, Risk Assessment can be done at multiple levels - risks involving organization, business unit, project, function, information asset, technology, people and...
Kulasekaran Satagopan
csksekar
Offline Send Email
May 11, 2007
6:03 am
189
Dear ISO-27001 Members, Salam/Namaste As I have already introduce myself in this forum, By the way This is Suneel Kumar Panjwani doing Consultancy of...
Suneel Panjwani
suneelnp
Offline Send Email
Jun 12, 2007
4:16 pm
190
Suneel - You need to speak to the HR dept head to list the processes that exist in the organization. But, nevertheless, you may have a few processes like...
Dhananjaya Naronikar
djisms
Offline Send Email
Jun 13, 2007
7:55 pm
191
  Hi.. This is Dinesh.. Can somebody help me in preparing the legal requirements w.r.t ISMS. What are the thing to be considered while preparing the document?...
Dinesh
dina_kd
Offline Send Email
Jun 16, 2007
5:09 am
192
  dear Dinesh, You can consider, Licence of Softwares, IT Act 2000 with this you can cosider Labaour laws, ... dear Dinesh, You can consider, Licence of...
Ankur
sangalankur
Offline Send Email
Jun 16, 2007
11:08 am
193
Hi Dinesh, The first thing on legal requirement is to consider the retention of logs. What logs to be retained and how long an organization is expected to...
Bala Ramanan
balaramanan2000
Offline Send Email
Jun 16, 2007
5:38 pm
194
Legal requirement in ISo 27001 requires you to identify applicable legislations such as IT ACT 200, Copyright Act, patent Act, privacy laws etc... that impact...
VIKRAM V
vikram7000
Offline Send Email
Jun 18, 2007
6:34 am
195
Hi Dinesh, I would suggest you take a look at all the applicable laws for your organization, right from Labour laws, shops and establishment act, IT act etc. ...
Dhananjaya Naronikar
djisms
Offline Send Email
Jun 18, 2007
2:20 pm
196
Hi all, Thanks for your comments...!!! Can anyone suggest me what are the Indian Acts needed to be covered in the legal register??. (Does anyone sensibily &...
Dinesh
dina_kd
Offline Send Email
Jun 18, 2007
2:23 pm
197
Hello, We are thinking on working on the process to get certified BS7799/ISO270001. My boss ask me to plan for this activity specialy for what we need help...
kais-b
Offline Send Email
Jun 19, 2007
3:16 pm
198
... These figures for a substantial enterprise - small and medium sized businesses will be less. Good consultants will run on the order of $125K to do the...
Fred Cohen
fcallnet
Offline Send Email
Jun 19, 2007
4:30 pm
199
KB: 1. Very hard to say without knowing how big your company is. I'd say you need a month in the beginning, and may be more. 2. Yes, you can have the initial...
Javed Ikbal
javed_ikbal
Offline Send Email
Jun 19, 2007
4:30 pm
200
... You can use my templates to estimate the number of days you need based on your self-gap-analysis. My template is a combination of 27000 & COBIT generic...
Chandra Yulistia
chandrayulistia
Offline Send Email
Jun 20, 2007
1:25 pm
201
Dear KB, ISO27001:2005 Certification: Cost for ISO27001 certification (UKAS Accrediated) Indian Rs. 45,000.00 upto 50 nodes or employee and 65,000.00 upto 100...
Ankur
sangalankur
Offline Send Email
Jun 21, 2007
3:45 pm
202
Dinesh, Following are some of the Indian Leagal requirements: IT Act 2000 Copyright Act 1952 STPI Regulations Evidence Act · Indian Factories Act,...
Hi Conf
hiconf
Offline Send Email
Jun 21, 2007
3:46 pm
203
On Laws...here are some... Indian It Act 2000, Provident Fund Act, Employee State Insurance, Worker's Compensation, Payment Of Gratuity Act, <State> Shops & ...
Antony Rexon
antonyrexon
Offline Send Email
Jun 21, 2007
3:46 pm
204
  Hi.. Thanks for your input. I do agree we have to take of IT Act 2000, Copyright Act 1952 etc. I'm not able to understand why we have take care of acts like...
Dinesh
dina_kd
Offline Send Email
Jun 22, 2007
2:10 pm
205
Hi Dinesh They are all part of information systems recycle/reuse/disposal processes. For ex. usage of electronic equipments such as PC monitors may mandate...
Venu
venu_kailas
Offline Send Email
Jun 23, 2007
6:13 am
206
Dinesh, In simple terms the control manadates you to identify & follow all the relevant laws and regulation. Think.., in case if your organisation do not...
Hi Conf
hiconf
Offline Send Email
Jun 25, 2007
7:49 pm
Messages 177 - 206 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help