Search the web
Sign In
New User? Sign Up
iso-27001 · ISO 27001
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 318 - 347 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
318
Thanks a lot for ur valuable replies. Now I've a clear idea of it; so I can go ahead with reading the Risk assessment part in detail for ISO 27001...
swatibahekar
Offline Send Email
Sep 2, 2008
7:27 am
319
There are really a lot of policies on the web...However,email policies need to be drafted only after careful screening of the process,users,etc...How can you...
l_shankar2003
Offline Send Email
Sep 3, 2008
7:07 am
320
When defining the asset inventory and asset value can they be done at the same time or first you need to do the Asset inventory and then the asset value? How...
rijbob
Offline Send Email
Sep 21, 2008
8:08 am
321
The short answer is it depends :-) It depends on the nature of the information you are looking to classify. If it is structured data, as within a database or...
Eric
bonnele13
Offline Send Email
Sep 21, 2008
6:26 pm
322
First you need to collect the inventory of all assets and then you have to calculate the value of each asset based on the importance and criticality of each...
atul patel
atul_ya
Offline Send Email
Sep 21, 2008
6:27 pm
323
Rant ON And how do you calculate? What is the role of the asset for your business - In what units do you measure this? How important it is. Same as above. What...
Vicente Aceituno
aceituno
Offline Send Email
Sep 22, 2008
7:25 am
324
Let me put it this way - 1) Asset Inventory needs to be "Information Assets" Inventory and not "IT Asset Inventory" as seen by many people. Irrespective of the...
Dhananjaya Naronikar
djisms
Offline Send Email
Sep 23, 2008
8:01 am
325
Hi I am confsed with Risk Management for CMMI and Risk Assessment for ISO27001. ISO27001 talks about  assest wise risk assessment whereas CMMi RM talks about...
ashish sharma
ashu_oct
Offline Send Email
Sep 23, 2008
8:01 am
326
Hi Mathi E Arasu I do agree with you but in a organisation we have to maiintain two different docs or approach for assessing the risk. it will be very...
ashish sharma
ashu_oct
Offline Send Email
Sep 23, 2008
8:01 am
327
All these measurements are qualitative.   egs : assign 1 2 or 3 for confidentiality and define the levels qualitatively. You can similarly define availability...
shankar moorthy
l_shankar2003
Offline Send Email
Sep 23, 2008
8:01 am
328
Hi Ashish, Why do you have to have two RAs? Only one will do. You said CMMI RA deals with project. Well, what are the components of your project? Are they...
Eric Regalado
er_regalado
Offline Send Email
Sep 23, 2008
7:15 pm
329
Hi All, A recent risk review identified data leakage as one the major risks facing my organisation. The use of USB pens and CD drives is an obvious methods of...
andypowell100
Offline Send Email
Sep 23, 2008
7:15 pm
330
... Andy, If you're using Active Directory you can disable USB/CD-ROM write access via a global policy that's pushed to the workstations and servers. If...
jasonvmiller
Offline Send Email
Sep 24, 2008
7:28 am
331
Why dont u consider PS/2 ports for Keyboard/mouse and remove/disable the USB Permanently??  Shankar Kris 1 847 363 1675 ... From: andypowell100...
shankar moorthy
l_shankar2003
Offline Send Email
Sep 24, 2008
7:28 am
332
Hi Andy,   There is a possibility of disabling USB and External Drives - whith which depends on user account or groupings as set in the Organizational Unit's...
Mervs Palmores
mervs06
Offline Send Email
Sep 24, 2008
7:28 am
333
Hi All,   In my organistion we use CSA (Cisco Security Agent) to prevent data leakage through USB pen.   Bhavesh ... From: jasonvmiller...
Bhavesh Pandey
bhavesh.pandey
Offline Send Email
Sep 24, 2008
8:02 pm
334
On Tue, Sep 23, 2008 at 6:50 PM, andypowell100 ... You can try installing some software on the PCs which encrypts the data on the pen drive. So, if you write...
Sudhanwa Jogalekar
sudhanwa_jog...
Offline Send Email
Sep 24, 2008
8:02 pm
335
Hi Andy,   TAKE A BACK UP OF YOUR REGISTRY BEFORE TRYING THIS.   Go to regedit,   HKEY_LOCAL_ MACHINE>SYSTEM>CurrentControlSet>Control Right click-new key,...
Abhilash P
abhi_ssa
Offline Send Email
Oct 2, 2008
6:14 pm
336
The new issue has just arrived. I am posting it below for the group. Laura ______________________________________________________ THE ISO 27001 and ISO 27002...
laurahamp
Offline Send Email
Oct 28, 2008
11:07 am
337
At a very high level, in order to fulfill physical requirements what is are the minimum things we need to consider: For ex: generator, video cameras, access...
rijbob
Offline Send Email
Oct 29, 2008
8:35 am
338
Hi, While implementing ISo27001 standard for an organization, which law takes the precedence international law or the country law.For eg: in countries which...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
Nov 12, 2008
6:23 pm
339
Hi Rizwan I don't have the standard in front of me, and I don't remember exactly what it says on the issue of software licensing, but in my opinion, there are...
John Annen
rjannen
Offline Send Email
Nov 13, 2008
10:43 am
340
Which countries are saying there is no need to buy licensed software? Can you share laws from these countries saying it is ok to use unlicensed software? FYI,...
Eric Regalado
er_regalado
Offline Send Email
Nov 13, 2008
10:43 am
341
It exactly dont say anything about the licenses but it talked about protection of intellectual property in which licenses are also included....
Syed Faraz Javed
maverick_inv...
Offline Send Email
Nov 13, 2008
8:02 pm
342
... Can't say anything to that topic, but would be interested in the laws, which says, you don't need to buy the stuff you're working with.. ;-) ... Yea..-No. ...
Andreas Rauer
Andreas.Rauer@...
Send Email
Nov 13, 2008
8:02 pm
343
Agree with Eric....No-one is allowed to use pirated software by law...sanction or no sanction.If they use it,the it is not ethical. Shankar Kris 1 847 363 1675...
shankar moorthy
l_shankar2003
Offline Send Email
Nov 13, 2008
8:02 pm
344
The purpose of legal compliance being part of the security requirements is to prevent legal risks affecting the business continuity. Under this principle, if...
Na.Vijayashankar
naavi3699
Offline Send Email
Nov 13, 2008
8:02 pm
345
Dear All,I have small doubt. Can we add this wording in the certification scope "....support functions including data protection act of UK 1998..." ??? My...
Nagendra Venkobarao
vsnagi
Offline Send Email
Nov 25, 2008
9:21 am
346
Why do you want to do that? You can if you want but the scope statement is not the proper place to add such words. Regards, Richard ...
Eric Regalado
er_regalado
Offline Send Email
Nov 25, 2008
7:03 pm
347
IMHO, If you are gunning for ISO27001 Certification, you need to show compliance only to that standard. While compliance to other standards/ Regulations is...
Sarang Kelkar
ssarangvkelkar
Offline Send Email
Nov 25, 2008
7:03 pm
Messages 318 - 347 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help