Search the web
Sign In
New User? Sign Up
iso-27001 · ISO 27001
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Show off your group to the world. Share a photo of your group with us.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 386 - 415 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
386
Hi Tarek I would like to draw your attention to the below peice of information extracted from ISO 17799/ISO 27002 - the COP. c) physical assets: computer...
Dhananjaya Naronikar
djisms
Offline Send Email
May 1, 2009
5:11 pm
387
First you need to fully understand the Business Processess under the scope. And only include those assets that efect the business process. The assets that...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
May 5, 2009
8:41 am
388
There isa no standard method for doing it. Do you need RART template..you can find oon the internet. For any help on RART u can refer Clauses of ISO 27001.   ...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
May 5, 2009
8:42 am
389
Hi, You can refer to ISO 27005, which is very easy to understand and implement. Hope this helps. Thanks and best regards, Nagi To: iso-27001@yahoogroups.com ...
Nagendra Venkobarao
vsnagi
Offline Send Email
May 5, 2009
6:39 pm
390
Hi Siddi, Would you mind to give me what "PART" standing for? Best regards, Krit. ... From: Siddi Rizwaan Damad <siddirizwaan@...> Subject: Re:...
Teerakrit Juntabenjapat
teerakrit
Offline Send Email
May 5, 2009
6:39 pm
391
Hi, RART means Risk Assessment and Risk Treatment(mitigation). You can use your own method for RART. But it should be logical, practical and cover all aspects...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
May 7, 2009
8:29 am
392
thank you all we start to study ISO 27005, NIST SP 800-30 Risk Management Guide for Information Technology System, and ISO guide 73. initialy I think it's...
sideeeg
Offline Send Email
May 7, 2009
6:16 pm
393
Hi All, Is the capacity Planning  control necessary? Coz I feel dynamic business like BPO or ISP may need capacity planning. But for business that grow but...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
May 10, 2009
6:04 pm
394
Sigh. No control is mandatory or necessary as long as you can justify the reason for not using the control. Richard ________________________________ From:...
Eric Regalado
er_regalado
Offline Send Email
May 11, 2009
8:29 am
395
Hi, If you can show the auditor that the 'availability' of the business processes is not affected by the 'x' months planning, then there are no issues.......
Dhananjaya Naronikar
djisms
Offline Send Email
May 11, 2009
10:13 pm
396
Hi all, I'm relatively new to an organisation in which the security team has applied ISO27001 to a small portion of the estate (3 applications out of over...
Nigel Beard
nigelbeard98
Offline Send Email
May 13, 2009
8:28 am
397
I'm relatively new to an organisation in which the security team has applied ISO27001 to a small portion of the estate (3 applications out of over 400). The...
nigelbeard98
Offline Send Email
May 13, 2009
8:28 am
398
Hi ! I think the auditors mostly look for the INTENT in the documented processes.   In this case you can show some logical calculation like say ...10 GB...
manish dave
manish_dave
Offline Send Email
May 13, 2009
8:29 am
399
Nigel: Starting ISO27001 on a limited scope is perfectly acceptable (actually, recommended), as long as it is considered to be part of strategy that will...
Javed Ikbal
javed_ikbal
Offline Send Email
May 14, 2009
7:53 am
400
Dear All,   Please can anyone give me an update on how to implement ISO 27001 with COBIT.   Thanks. Dear All, Please can anyone give me an update on how to...
Okunwa Aduragbemi
adura4u2nv
Offline Send Email
May 29, 2009
7:11 am
401
Hi ISACA has a download of the COBIT & ISO 27001 mapping. Maybe that will help you. Cheers, Dhananjaya Rao.N   ________________________________ From: Okunwa...
Dhananjaya Naronikar
djisms
Offline Send Email
Jun 2, 2009
6:48 am
402
Hi , there are a lot of documents on net showing Cobit and ISo 27001 mapping.   RD ... From: Okunwa Aduragbemi <adura4u2nv@...> Subject: [iso-27001]...
Siddi Rizwaan Damad
siddirizwaan
Offline Send Email
Jun 2, 2009
6:48 am
403
Does anyone know the potential pitfalls of applying ISO controls to processes? My organisation is mooting an expansion of our registration to all of our top 40...
nigelbeard98
Offline Send Email
Jun 3, 2009
6:49 pm
404
Considering the client follows ISO 17799:2005 ISMS, when does the client define "Management responsibility"? a. standards are defined b. assets are identified ...
RiCkY
deepal.madlani
Offline Send Email
Jul 16, 2009
7:35 am
405
Hi, 2 cents from me - Clause 5 (Mandatory clauses) clearly explains that the Management Responsibility has to be set up before the start of implementation and...
Dhananjaya Naronikar
djisms
Offline Send Email
Jul 17, 2009
9:20 am
406
Management responsibilities comes in cl 6.1.1 as management commitment. This is mandentory guidelines of ISO 17799:2005. It comes after policy documents are...
Bhavesh Pandey
bhavesh.pandey
Offline Send Email
Jul 18, 2009
8:31 am
407
I appreciate your response. I am clear about the Clause 5. however, which is the best answer to choose from the options provided was my query. Thanks, Deepal ...
RiCkY
deepal.madlani
Offline Send Email
Jul 18, 2009
8:31 am
408
Dear all, I have few questions on control A11.7.2 implementation.  1. What is the normal trend on allowing users to work from home? 2.  Should they be...
balasaheb ware
balaware
Offline Send Email
Jul 18, 2009
8:31 am
409
Duh? Why do you need to "define" management responsibility? ________________________________ From: RiCkY <madlaniricky@...> To: iso-27001@yahoogroups.com...
Eric Regalado
er_regalado
Offline Send Email
Jul 20, 2009
7:33 am
410
Dear All,   I need clarification on how to go about the implementation of the Statement of Applicability.   How do i know the yardstick for determining the...
Okunwa Aduragbemi
adura4u2nv
Offline Send Email
Jul 21, 2009
7:42 am
411
... Hallo Deepal, ISO 27002:2005 (formerly known as ISO 17799:2005) is not necesseraly implemented starting at chapter 1 and ending at chapter 15, in that...
hwkeijzer
Offline Send Email
Jul 21, 2009
7:42 am
412
Hi we are implementing ISMS and would like to know what will be the best way for risk management and assessment we worked on the FMEA procedure but I am not...
niru.live
Offline Send Email
Jul 21, 2009
7:42 am
413
hi is there any change in the SOA if the scope of ISMS is limited to IT department. please revert. niranjan...
niru.live
Offline Send Email
Jul 21, 2009
7:42 am
414
Eric, thats how the question was framed by the certification body :) ________________________________ From: Eric Regalado <er_regalado@...> To:...
RiCkY
deepal.madlani
Offline Send Email
Jul 21, 2009
7:43 am
415
Yes, there will be changes in the SOA. Note: It all depends on the scope defined initially. If you change the scope all documents related to ISMS will get...
Dharmendra
dharmu_r
Online Now Send Email
Jul 21, 2009
4:40 pm
Messages 386 - 415 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help