Search the web
Sign In
New User? Sign Up
iso-27001 · ISO 27001
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Show off your group to the world. Share a photo of your group with us.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 361 - 390 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
361
Is certification only for production systems or can it be for development and test systems?...
sqamar95
Offline Send Email
Mar 18, 2009
8:27 am
362
... It includes test and development!!! u can not separate them...
oguzhanssan
Offline Send Email
Mar 18, 2009
8:46 pm
363
Hi The certification is for management system, it can be any management system( Production, testing or design and development anything). May be a call centre,...
Vikas Dhanker
dhankervikas
Offline Send Email
Mar 19, 2009
8:28 am
364
Of course you can. Certification is dependent on the scope. Richard ________________________________ From: oguzhanssan <oguzhanssan@...> To:...
Eric Regalado
er_regalado
Offline Send Email
Mar 20, 2009
8:19 am
365
... yes in fact or theory u can but if auditor asks that how you include new systems to whole system and if u say directly then u have to define your risks at...
oguzhanssan
Offline Send Email
Mar 20, 2009
6:42 pm
366
Our consultant claims that the Auditor can do Phase 1 and Phase 2 audit in a one, 3 days trip, is this true? Is there any rule about Phase 1 and Phase 2 audits...
Tarek El kinawi
tarekelkinawi
Offline Send Email
Mar 20, 2009
6:42 pm
367
Yes it is possible. Stage 1 is checking your management system in "theory". Stage 2 is checking the application or implementation. If you pass Stage 1 or if...
Eric Regalado
er_regalado
Offline Send Email
Mar 23, 2009
9:14 am
368
My scope is dependent on my business needs and not what the auditor think. I don't care what the auditor think about my scope. At the end of the day,...
Eric Regalado
er_regalado
Offline Send Email
Mar 23, 2009
9:14 am
369
... ISO/IEC 27006:2006 "Requirements for bodies providing audit and certification of information security management systems" defines follwing: <snippet> ...
Andreas Rauer
Andreas.Rauer@...
Send Email
Mar 23, 2009
9:15 am
370
Hi friends,   Can anyone help me what the ISMF (Information Security Management Forum) should exactly do? I would appreciate if anyone could send me the roles...
tsunami anami
tsunami_anami
Offline Send Email
Mar 23, 2009
6:45 pm
371
Hi Guys,   I am in the process of preparing a GAP analysis report for ISMS implementation in our company. Can any one suggest me how to do the cost benifit...
nirmal kumar
mnirk81
Offline Send Email
Mar 25, 2009
9:27 am
372
Hello All, I’m relatively new over here, as the company I belong to also looking for the implementation and certification of ISO 27001. By going through the...
Hassham Idris
gr8_libra2002
Offline Send Email
Mar 25, 2009
9:28 am
373
I dont think any body will be able to help you on this... If there ia anything regarding the standard you can contact again. For equipments you need to get in...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
Mar 25, 2009
6:42 pm
374
·         Ensuring that Information security objectives and plans are established for ISMS. ·         Communicating to the organization the...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
Mar 25, 2009
6:45 pm
375
You will need to find the threats to assets in business process, then find the vulverability that can expolit that threat. After doing this, you need to find...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
Mar 25, 2009
6:48 pm
376
hello all i am question threat catalog for risk analysis. attention: risk function=R if dependent variables = V(vulnerability) and T(theat) R(V,T) i used...
Zuhtu Kayali
zuhtukayali
Online Now Send Email
Mar 25, 2009
6:48 pm
377
None is required. Additional investment shall be commensurate to your risks and business needs. Richard Regalado ________________________________ From: Siddi...
Eric Regalado
er_regalado
Offline Send Email
Mar 27, 2009
8:33 am
378
Our consultants want us to add all our company workstations in the Assets inventory list, is this correct? I believe that we should only add the workstations...
Tarek El kinawi
tarekelkinawi
Offline Send Email
Apr 26, 2009
6:56 pm
379
Hi Tarek, I thinks workstation shuold in the assets list because the workstaion can effect to availablility. Nam From VietNam. ... From: Tarek El kinawi...
hoang nam
cangua166@...
Send Email
Apr 27, 2009
7:36 am
380
Tarek, It depends on the topology of the network. If both assets containing non-sensative and sensative data reside on the same network and/or are routeable...
Wayne
secgauntlet
Offline Send Email
Apr 27, 2009
7:37 am
381
As per ISO 27001: an organization should maintain an updated asset inventory. In this case the consultant is telling right. This task can be designated to some...
Dharmendra
dharmu_r
Offline Send Email
Apr 27, 2009
8:07 pm
382
All the assets which affects the security CIA triad ie confidentiality, Integrity and availability needs to be considered in the asset. Desktops although does...
Ramsy Lasrado
ramsy856
Offline Send Email
Apr 27, 2009
8:07 pm
383
Hi every one, this my first message We did assets inventory, now we start the risk assessment phase, We need to know the available risk assessment...
sideeeg
Offline Send Email
Apr 29, 2009
7:46 am
384
Thank you all for your feed back. I am getting 3 directions from the feed back: 1- Consider all the workstations in the assets inventory. So consider the asset...
tarek@...
tarekelkinawi
Offline Send Email
Apr 29, 2009
7:47 am
385
Is it the work flow or business flow is what decides what to include and execlude?   ... From: tarek@... <tarek@...> Subject: Re: Re:...
Aladdin Afifi
mr_afifi
Offline Send Email
Apr 29, 2009
5:26 pm
386
Hi Tarek I would like to draw your attention to the below peice of information extracted from ISO 17799/ISO 27002 - the COP. c) physical assets: computer...
Dhananjaya Naronikar
djisms
Offline Send Email
May 1, 2009
5:11 pm
387
First you need to fully understand the Business Processess under the scope. And only include those assets that efect the business process. The assets that...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
May 5, 2009
8:41 am
388
There isa no standard method for doing it. Do you need RART template..you can find oon the internet. For any help on RART u can refer Clauses of ISO 27001.   ...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
May 5, 2009
8:42 am
389
Hi, You can refer to ISO 27005, which is very easy to understand and implement. Hope this helps. Thanks and best regards, Nagi To: iso-27001@yahoogroups.com ...
Nagendra Venkobarao
vsnagi
Offline Send Email
May 5, 2009
6:39 pm
390
Hi Siddi, Would you mind to give me what "PART" standing for? Best regards, Krit. ... From: Siddi Rizwaan Damad <siddirizwaan@...> Subject: Re:...
Teerakrit Juntabenjapat
teerakrit
Offline Send Email
May 5, 2009
6:39 pm
Messages 361 - 390 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help