Search the web
Sign In
New User? Sign Up
iso-27001 · ISO 27001
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 230 - 259 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
230
Hi, I have a doubt. Assuming that we have a device (say an Oscilloscope) which is used for initial testing of a product. This device does not contain any...
Jagdish Rao
rao_jags
Offline Send Email
Sep 4, 2007
8:17 am
231
Hi, Yet another doubt. How do we identify a scope of implementation ? I am not able to word it out. Can i get some samples ? Thanks Regards Jagdish ... Once...
Jagdish Rao
rao_jags
Offline Send Email
Sep 4, 2007
8:18 am
232
Hello Mr.Rao During Asset Modelling we take all the HW, SW and Information Assets (Critical and Non-Critical) into account. So with this theory Oscilloscope is...
neerkuma
Offline Send Email
Sep 4, 2007
4:43 pm
233
Hello Jagdish, From what I understand, ISO 27001 requires us to identify assets that fall within the scope of the ISMS. (Refer to: ISO/IEC 27001:2005, in ...
Sarang
ssarangvkelkar
Offline Send Email
Sep 4, 2007
4:46 pm
234
Hi, To add to this, I feel you can consider Oscilloscope as an asset. If you have made an inventory of assets and classified them, you can consider this under...
Shweta Kshirsagar
schweta_k2
Offline Send Email
Sep 5, 2007
7:20 am
235
Hi ! I look at it this way : Assets to be considered in classification are 1. Information assets (which hold/stage information) 2. Information processing...
manish dave
manish_dave
Offline Send Email
Sep 5, 2007
12:20 pm
236
Hi, I had been reading the following discussion, I kind of agree with Manish. We are currently implementing ISMS. We are done with the risk assessment. Now are...
Abhishek Maurya
abhi9211
Offline Send Email
Sep 5, 2007
5:42 pm
237
Hi Abhishek, I agree with you that RA & BIA are confusing. Excerpts from a book : "Risk Analysis involves identifying the most probable threats to an...
manish dave
manish_dave
Offline Send Email
Sep 7, 2007
7:45 am
238
Dear Manish, Thank you very much for your thoughts on this. This helps a lot. As per the Excerpts from the book, my critical business function at the ...
Abhishek Maurya
abhi9211
Offline Send Email
Sep 8, 2007
7:44 am
239
Hi all, i agree to what has been discussed below. in case of oscilloscope. Confidentiality cud be rated N.A. while integrity and availability cud be kept HIGH....
RiCkY
deepal.madlani
Offline Send Email
Sep 8, 2007
9:56 am
240
Hi, My 2 cents on this topic.... In a typical BIA - you are going to specifically capture information related to 2 main important areas - Recovery Time...
Dhananjaya Naronikar
djisms
Offline Send Email
Sep 10, 2007
12:13 pm
241
Hello, Has anyone reviewed/ audited/ carried out a Risk Assessment or Business Impact Analysis for a Central Bank environment? If so, please share any...
Dee
dmutitu
Offline Send Email
Sep 13, 2007
8:05 pm
242
Hello, Has anyone reviewed/ audited/ carried out a Risk Assessment or Business Impact Analysis for a Central Bank environment? If so, please share any...
habibollah tavakalou
urs.auditor
Offline Send Email
Sep 14, 2007
12:39 pm
243
I am researching on how various risk assessment tools compare to each other. Has any of you used one or more of the following, and how do you compare them in...
rufina_achieng
Offline Send Email
Sep 25, 2007
10:51 am
244
Two major tools to add to your list: COBRA CRAMM The former is far easier to use than the latter, but both do have significant international user bases....
laurahamp
Offline Send Email
Sep 25, 2007
12:51 pm
245
Dear All, Can you please explain what is acceptance criteria as mentioned in the below lines: "Organisation will ensure that acceptance procedures are carried...
maseafsuae s
maseafsuae123
Offline Send Email
Sep 25, 2007
12:52 pm
246
You might want to look at ISO 27001 (was 17799:2005) to get an idea of the acceptance criteria likely to be expected. FC ... - This communication is...
Fred Cohen
fcallnet
Offline Send Email
Sep 25, 2007
5:22 pm
247
Dear Rufina, ... I can think of the following criteria: - The scope (what's in, what's out) - Is the organization modelled as a bunch of assets, or is another...
Vicente Aceituno
aceituno
Offline Send Email
Sep 25, 2007
5:22 pm
248
Great work is in progress.. we would be waiting for your research papers once they are published. hope it would help the Risk Assessment Market. You can also...
RiCkY
deepal.madlani
Offline Send Email
Sep 25, 2007
5:23 pm
249
Maybe this is methodology ? Octave NIST 800 series (I forgot about the number) _____ From: rufina_achieng [mailto:rufina_achieng@...] Sent: Tuesday,...
Adi Primadi
adi@...
Send Email
Sep 26, 2007
7:37 am
250
... OCTAVE is methodology. BS 31100 (under dev.) is addressing Risk management in general, as well as ISO 31000 (also under dev., currently 1st Committee...
Andreas Rauer
Andreas.Rauer@...
Send Email
Sep 26, 2007
10:54 am
251
Hi, I am asked to do a Risk Assessment / Business impact Analysis before we begin with getting the Data classified for implementation of ISMS. Not really sure...
mvssubbu
Offline Send Email
Oct 7, 2007
7:49 am
252
Hi Subramanian, You can refer the ISO/IEC 27001:2005 standard for a complete understanding of what needs to be done, like first understand the...
Dhananjaya Naronikar
djisms
Offline Send Email
Oct 8, 2007
11:15 am
253
The latest edition just arrived: THE ISO 27001 and ISO 27002 NEWSLETTER - EDITION 16 ______________________________________________________ Welcome to Issue 16...
laurahamp
Offline Send Email
Oct 9, 2007
9:27 am
254
Hello All, I am working in Big Consulting organization with strength of around 18K employees,i am working as an INFOSEC Consultant. i am drafting Policy on...
Samir Shah
samcool80
Offline Send Email
Oct 13, 2007
8:10 am
255
Hi, There are tools available (like bellarc) to identify all applications in a machine / network. With this information you can talk with IT department (or...
Bala Ramanan
balaramanan2000
Offline Send Email
Oct 15, 2007
8:45 am
256
The latest issue has just landed. See below. Laura ______________________________________________________ THE ISO 27001 and ISO 27002 NEWSLETTER - EDITION 17 ...
laurahamp
Offline Send Email
Jan 21, 2008
8:24 pm
257
Hi all, Can anyone help me out in making a list of do's and don'ts for giving it to my office security personnel instead of training them everytime when the...
Madhavi Alapati
alapatimadhavi
Offline Send Email
Jan 30, 2008
9:06 am
258
Hi, It would be very simple... a quick solution would be to go through the activity that a Physical Security personal needs to do on a daily basis.... Like...
Dhananjaya Naronikar
djisms
Offline Send Email
Feb 1, 2008
8:55 pm
259
I would like to say that ... Training is mandatory for the security personal, since Information Security is not just a checklist.... you shall train them how...
Vikas Dhanker
dhankervikas
Offline Send Email
Feb 2, 2008
9:12 am
Messages 230 - 259 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help