Search the web
Sign In
New User? Sign Up
iso-27001 · ISO 27001
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 223 - 252 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
223
Hi Scott, What is the normal process for a standard to become ISO, apart from those you have already explained, also what is the criteria and how this has to...
Antony Rexon
antonyrexon
Offline Send Email
Aug 2, 2007
6:51 am
224
Hi. I am new to the group. Often I have tried to obtain employment in the field of IT security. I have a lot of practical technical experience in the field. ...
Cyberlink
cyberlink@...
Send Email
Aug 2, 2007
1:14 pm
225
... Thanks Scott! :P Jay...
jasonvmiller
Offline Send Email
Aug 3, 2007
8:21 am
226
The newsletter just arrived. See below. Laura ______________________________________________________ THE ISO 27001 and ISO 17799 NEWSLETTER - EDITION 15 ...
laurahamp
Offline Send Email
Aug 3, 2007
10:19 am
227
I was just working through the ISO 27001 document again and, thanks to a customer question, I have one. Has anyone else noticed that in section 4.2.1 item g it...
Fred Cohen
fcallnet
Offline Send Email
Aug 17, 2007
8:17 pm
228
Dear Fred, The item you are referring to is 4.2.3 (g) of the ISO 27001 document, if I am correct. If you look at the next item 4.2.4, it brings out the spirit...
Vijendera Kaushik
vijenderkk
Offline Send Email
Aug 18, 2007
7:12 am
229
Vijendera, All of which makes my point. There is nothing defined as a "Security Plan" - the term is generic, not specific. It is a poor choice of wording...
Fred Cohen
fcallnet
Offline Send Email
Aug 18, 2007
7:59 pm
230
Hi, I have a doubt. Assuming that we have a device (say an Oscilloscope) which is used for initial testing of a product. This device does not contain any...
Jagdish Rao
rao_jags
Offline Send Email
Sep 4, 2007
8:17 am
231
Hi, Yet another doubt. How do we identify a scope of implementation ? I am not able to word it out. Can i get some samples ? Thanks Regards Jagdish ... Once...
Jagdish Rao
rao_jags
Offline Send Email
Sep 4, 2007
8:18 am
232
Hello Mr.Rao During Asset Modelling we take all the HW, SW and Information Assets (Critical and Non-Critical) into account. So with this theory Oscilloscope is...
neerkuma
Offline Send Email
Sep 4, 2007
4:43 pm
233
Hello Jagdish, From what I understand, ISO 27001 requires us to identify assets that fall within the scope of the ISMS. (Refer to: ISO/IEC 27001:2005, in ...
Sarang
ssarangvkelkar
Offline Send Email
Sep 4, 2007
4:46 pm
234
Hi, To add to this, I feel you can consider Oscilloscope as an asset. If you have made an inventory of assets and classified them, you can consider this under...
Shweta Kshirsagar
schweta_k2
Offline Send Email
Sep 5, 2007
7:20 am
235
Hi ! I look at it this way : Assets to be considered in classification are 1. Information assets (which hold/stage information) 2. Information processing...
manish dave
manish_dave
Offline Send Email
Sep 5, 2007
12:20 pm
236
Hi, I had been reading the following discussion, I kind of agree with Manish. We are currently implementing ISMS. We are done with the risk assessment. Now are...
Abhishek Maurya
abhi9211
Offline Send Email
Sep 5, 2007
5:42 pm
237
Hi Abhishek, I agree with you that RA & BIA are confusing. Excerpts from a book : "Risk Analysis involves identifying the most probable threats to an...
manish dave
manish_dave
Offline Send Email
Sep 7, 2007
7:45 am
238
Dear Manish, Thank you very much for your thoughts on this. This helps a lot. As per the Excerpts from the book, my critical business function at the ...
Abhishek Maurya
abhi9211
Offline Send Email
Sep 8, 2007
7:44 am
239
Hi all, i agree to what has been discussed below. in case of oscilloscope. Confidentiality cud be rated N.A. while integrity and availability cud be kept HIGH....
RiCkY
deepal.madlani
Offline Send Email
Sep 8, 2007
9:56 am
240
Hi, My 2 cents on this topic.... In a typical BIA - you are going to specifically capture information related to 2 main important areas - Recovery Time...
Dhananjaya Naronikar
djisms
Offline Send Email
Sep 10, 2007
12:13 pm
241
Hello, Has anyone reviewed/ audited/ carried out a Risk Assessment or Business Impact Analysis for a Central Bank environment? If so, please share any...
Dee
dmutitu
Offline Send Email
Sep 13, 2007
8:05 pm
242
Hello, Has anyone reviewed/ audited/ carried out a Risk Assessment or Business Impact Analysis for a Central Bank environment? If so, please share any...
habibollah tavakalou
urs.auditor
Offline Send Email
Sep 14, 2007
12:39 pm
243
I am researching on how various risk assessment tools compare to each other. Has any of you used one or more of the following, and how do you compare them in...
rufina_achieng
Offline Send Email
Sep 25, 2007
10:51 am
244
Two major tools to add to your list: COBRA CRAMM The former is far easier to use than the latter, but both do have significant international user bases....
laurahamp
Offline Send Email
Sep 25, 2007
12:51 pm
245
Dear All, Can you please explain what is acceptance criteria as mentioned in the below lines: "Organisation will ensure that acceptance procedures are carried...
maseafsuae s
maseafsuae123
Offline Send Email
Sep 25, 2007
12:52 pm
246
You might want to look at ISO 27001 (was 17799:2005) to get an idea of the acceptance criteria likely to be expected. FC ... - This communication is...
Fred Cohen
fcallnet
Offline Send Email
Sep 25, 2007
5:22 pm
247
Dear Rufina, ... I can think of the following criteria: - The scope (what's in, what's out) - Is the organization modelled as a bunch of assets, or is another...
Vicente Aceituno
aceituno
Offline Send Email
Sep 25, 2007
5:22 pm
248
Great work is in progress.. we would be waiting for your research papers once they are published. hope it would help the Risk Assessment Market. You can also...
RiCkY
deepal.madlani
Offline Send Email
Sep 25, 2007
5:23 pm
249
Maybe this is methodology ? Octave NIST 800 series (I forgot about the number) _____ From: rufina_achieng [mailto:rufina_achieng@...] Sent: Tuesday,...
Adi Primadi
adi@...
Send Email
Sep 26, 2007
7:37 am
250
... OCTAVE is methodology. BS 31100 (under dev.) is addressing Risk management in general, as well as ISO 31000 (also under dev., currently 1st Committee...
Andreas Rauer
Andreas.Rauer@...
Send Email
Sep 26, 2007
10:54 am
251
Hi, I am asked to do a Risk Assessment / Business impact Analysis before we begin with getting the Data classified for implementation of ISMS. Not really sure...
mvssubbu
Offline Send Email
Oct 7, 2007
7:49 am
252
Hi Subramanian, You can refer the ISO/IEC 27001:2005 standard for a complete understanding of what needs to be done, like first understand the...
Dhananjaya Naronikar
djisms
Offline Send Email
Oct 8, 2007
11:15 am
Messages 223 - 252 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help