Search the web
Sign In
New User? Sign Up
iso-27001 · ISO 27001
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 378 - 407 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
378
Our consultants want us to add all our company workstations in the Assets inventory list, is this correct? I believe that we should only add the workstations...
Tarek El kinawi
tarekelkinawi
Offline Send Email
Apr 26, 2009
6:56 pm
379
Hi Tarek, I thinks workstation shuold in the assets list because the workstaion can effect to availablility. Nam From VietNam. ... From: Tarek El kinawi...
hoang nam
cangua166@...
Send Email
Apr 27, 2009
7:36 am
380
Tarek, It depends on the topology of the network. If both assets containing non-sensative and sensative data reside on the same network and/or are routeable...
Wayne
secgauntlet
Offline Send Email
Apr 27, 2009
7:37 am
381
As per ISO 27001: an organization should maintain an updated asset inventory. In this case the consultant is telling right. This task can be designated to some...
Dharmendra
dharmu_r
Online Now Send Email
Apr 27, 2009
8:07 pm
382
All the assets which affects the security CIA triad ie confidentiality, Integrity and availability needs to be considered in the asset. Desktops although does...
Ramsy Lasrado
ramsy856
Offline Send Email
Apr 27, 2009
8:07 pm
383
Hi every one, this my first message We did assets inventory, now we start the risk assessment phase, We need to know the available risk assessment...
sideeeg
Offline Send Email
Apr 29, 2009
7:46 am
384
Thank you all for your feed back. I am getting 3 directions from the feed back: 1- Consider all the workstations in the assets inventory. So consider the asset...
tarek@...
tarekelkinawi
Offline Send Email
Apr 29, 2009
7:47 am
385
Is it the work flow or business flow is what decides what to include and execlude?   ... From: tarek@... <tarek@...> Subject: Re: Re:...
Aladdin Afifi
mr_afifi
Offline Send Email
Apr 29, 2009
5:26 pm
386
Hi Tarek I would like to draw your attention to the below peice of information extracted from ISO 17799/ISO 27002 - the COP. c) physical assets: computer...
Dhananjaya Naronikar
djisms
Offline Send Email
May 1, 2009
5:11 pm
387
First you need to fully understand the Business Processess under the scope. And only include those assets that efect the business process. The assets that...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
May 5, 2009
8:41 am
388
There isa no standard method for doing it. Do you need RART template..you can find oon the internet. For any help on RART u can refer Clauses of ISO 27001.   ...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
May 5, 2009
8:42 am
389
Hi, You can refer to ISO 27005, which is very easy to understand and implement. Hope this helps. Thanks and best regards, Nagi To: iso-27001@yahoogroups.com ...
Nagendra Venkobarao
vsnagi
Offline Send Email
May 5, 2009
6:39 pm
390
Hi Siddi, Would you mind to give me what "PART" standing for? Best regards, Krit. ... From: Siddi Rizwaan Damad <siddirizwaan@...> Subject: Re:...
Teerakrit Juntabenjapat
teerakrit
Offline Send Email
May 5, 2009
6:39 pm
391
Hi, RART means Risk Assessment and Risk Treatment(mitigation). You can use your own method for RART. But it should be logical, practical and cover all aspects...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
May 7, 2009
8:29 am
392
thank you all we start to study ISO 27005, NIST SP 800-30 Risk Management Guide for Information Technology System, and ISO guide 73. initialy I think it's...
sideeeg
Offline Send Email
May 7, 2009
6:16 pm
393
Hi All, Is the capacity Planning  control necessary? Coz I feel dynamic business like BPO or ISP may need capacity planning. But for business that grow but...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
May 10, 2009
6:04 pm
394
Sigh. No control is mandatory or necessary as long as you can justify the reason for not using the control. Richard ________________________________ From:...
Eric Regalado
er_regalado
Offline Send Email
May 11, 2009
8:29 am
395
Hi, If you can show the auditor that the 'availability' of the business processes is not affected by the 'x' months planning, then there are no issues.......
Dhananjaya Naronikar
djisms
Offline Send Email
May 11, 2009
10:13 pm
396
Hi all, I'm relatively new to an organisation in which the security team has applied ISO27001 to a small portion of the estate (3 applications out of over...
Nigel Beard
nigelbeard98
Offline Send Email
May 13, 2009
8:28 am
397
I'm relatively new to an organisation in which the security team has applied ISO27001 to a small portion of the estate (3 applications out of over 400). The...
nigelbeard98
Offline Send Email
May 13, 2009
8:28 am
398
Hi ! I think the auditors mostly look for the INTENT in the documented processes.   In this case you can show some logical calculation like say ...10 GB...
manish dave
manish_dave
Offline Send Email
May 13, 2009
8:29 am
399
Nigel: Starting ISO27001 on a limited scope is perfectly acceptable (actually, recommended), as long as it is considered to be part of strategy that will...
Javed Ikbal
javed_ikbal
Offline Send Email
May 14, 2009
7:53 am
400
Dear All,   Please can anyone give me an update on how to implement ISO 27001 with COBIT.   Thanks. Dear All, Please can anyone give me an update on how to...
Okunwa Aduragbemi
adura4u2nv
Offline Send Email
May 29, 2009
7:11 am
401
Hi ISACA has a download of the COBIT & ISO 27001 mapping. Maybe that will help you. Cheers, Dhananjaya Rao.N   ________________________________ From: Okunwa...
Dhananjaya Naronikar
djisms
Offline Send Email
Jun 2, 2009
6:48 am
402
Hi , there are a lot of documents on net showing Cobit and ISo 27001 mapping.   RD ... From: Okunwa Aduragbemi <adura4u2nv@...> Subject: [iso-27001]...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
Jun 2, 2009
6:48 am
403
Does anyone know the potential pitfalls of applying ISO controls to processes? My organisation is mooting an expansion of our registration to all of our top 40...
nigelbeard98
Offline Send Email
Jun 3, 2009
6:49 pm
404
Considering the client follows ISO 17799:2005 ISMS, when does the client define "Management responsibility"? a. standards are defined b. assets are identified ...
RiCkY
deepal.madlani
Offline Send Email
Jul 16, 2009
7:35 am
405
Hi, 2 cents from me - Clause 5 (Mandatory clauses) clearly explains that the Management Responsibility has to be set up before the start of implementation and...
Dhananjaya Naronikar
djisms
Offline Send Email
Jul 17, 2009
9:20 am
406
Management responsibilities comes in cl 6.1.1 as management commitment. This is mandentory guidelines of ISO 17799:2005. It comes after policy documents are...
Bhavesh Pandey
bhavesh.pandey
Offline Send Email
Jul 18, 2009
8:31 am
407
I appreciate your response. I am clear about the Clause 5. however, which is the best answer to choose from the options provided was my query. Thanks, Deepal ...
RiCkY
deepal.madlani
Offline Send Email
Jul 18, 2009
8:31 am
Messages 378 - 407 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help