Skip to search.

Breaking News Visit Yahoo! News for the latest.

×Close this window

iso-27001 · ISO 27001

The Yahoo! Groups Product Blog

Check it out!

Group Information

  • Members: 1113
  • Category: Security
  • Founded: May 28, 2005
  • Language: English
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Messages

Advanced
Messages Help
Messages 493 - 522 of 591   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand Author Sort by Date ^
493 Vikas Dhanker
dhankervikas Send Email
Apr 2, 2010
9:28 am
Eric It is possible that 14.1 is not applicable and thus you can take it as an excliusion. But it is not possible that yoou don't want to implement it so you...
494 Vikas Dhanker
dhankervikas Send Email
Apr 2, 2010
9:28 am
Hi Zahra Pen Test is not mandatory, but VA is mandatory. Now it depends upon the VA report whether PT is required or not. Depending upon the VA report ...
495 Dharmendra
dharmu_r Send Email
Apr 3, 2010
10:03 am
There are two ways of identifying NCs. 1) through internal audits 2) Security incidents Regards, Dharmendra T. ... -- Regards, Dharmendra T....
496 Eric Regalado
er_regalado Send Email
Apr 3, 2010
10:03 am
The fact that controls can be excluded mean they are NOT mandatory. Hence, NOT required. I don't want to implement BCP. I have something else better. :) ...
497 A V Achar
avachar Send Email
Apr 3, 2010
10:03 am
I do not agree with DJ.  A.14 cannot be excluded while implementing ISMS.  Yes, we do not talk aout BCP connected with entire business.  But in ISMS when we...
498 avachar Send Email Apr 3, 2010
10:03 am
You need not identify and mention 'potential non conformities&#39; with examples in the Procedure. The standard expect the management to document, in case you...
499 Eric Regalado
er_regalado Send Email
Apr 4, 2010
9:48 am
Sigh. ISO 27001 is clear on this matter. Controls CAN be excluded. The fact that controls CAN be excluded means that NO control is required as long as the...
500 Eric Regalado
er_regalado Send Email
Apr 4, 2010
9:51 am
Management will NOT use the preventive action procedure as much as the lower mammals in the organization. If examples, are not given, people would be left...
501 Siddi Rizwaan Damad
siddirizwaan Send Email
Apr 7, 2010
7:52 am
Hi all, I was also under the impression that BCP can be neglected. But the fact is it is one of the vital control when it comes to ISMS. How can the...
502 A V Achar
avachar Send Email
Apr 11, 2010
7:59 am
To all, As a matter of general rule, exclusions to controls is possible only in control domains A.9, A.10, A.11. and A.12. Exception to this rule is few and...
503 Eric Regalado
er_regalado Send Email
Apr 13, 2010
8:52 pm
Please don't say things that are not true Aleboor. What is the basis for your general rule? Which part of the standard says this? You said "As a matter of...
504 Eric Regalado
er_regalado Send Email
Apr 15, 2010
8:19 am
"Considered&quot; is different from "required";. ________________________________ From: Siddi Rizwaan Damad <siddirizwaan@...> To: iso-27001@yahoogroups.com ...
505 Deejay N
djisms Send Email
Apr 19, 2010
7:39 am
Eric is right here.   "Even some auditors insist that A14 should be considered." The above statement says it all - The problem is the way the...
506 Eric Regalado
er_regalado Send Email
Apr 20, 2010
8:17 am
Glad to know someone is one the right page. Cheers DJ. ________________________________ From: Deejay N <djisms@...> To: iso-27001@yahoogroups.com Sent:...
507 Ram B
b_ram_an Send Email
May 2, 2010
11:26 am
Just a thought.While I totally agree to the SoA point of view, there are some regulations that require that companies have Minimum Baseline standards that...
508 Deejay N
djisms Send Email
May 11, 2010
5:19 pm
Ram, While I can appreciate your thinking as an ISO of a Bank... I would like to draw your attention to the actual question "If BCP is optional" ... the...
509 K Mohan
k_mohan1965 Send Email
May 13, 2010
7:40 am
Dear Infosec People,   All my life, I was a part of ISO 9001 team, but recently my organization has entrusted me with an additional responsibility of ISO...
510 Dejan
dejan.kosutic Send Email
May 14, 2010
8:19 am
Hi Kumaraj, First of all, I'm not sure whether you are in a conflict of interest if you are part of the ISMS maintenance, and at the same time internal...
511 A V Achar
avachar Send Email
May 14, 2010
4:38 pm
 Dear Mohan, Knowledge of 9K is a good asset to understand 27K.  If you want to understand ISMS auditing, please read and digest the contents of ISO 27001...
512 manish dave
manish_dave Send Email
May 17, 2010
8:22 am
Usually people involved in ISMS implementation are from IT background. In the drive of implementing controls, we tend to forget that BCP is not confined to IT...
513 K Mohan
k_mohan1965 Send Email
May 19, 2010
8:01 am
Dear Friends, It seems you are not interested in helping this old man. At least, let me know what to be audited in Software Projects? Many of these projects...
514 Eric Regalado
er_regalado Send Email
May 19, 2010
6:42 pm
Dear Mohan, You need to audit the risk life cycle first. Don't audit the controls without first understanding the risks of the organization. Have you attended...
515 samminchin Send Email May 20, 2010
7:29 pm
Hi New to the forum, hope you can all help! I'm part of a small business (very small, 3 staff), currently looking at getting ISO certified, and I've been...
516 Eric Regalado
er_regalado Send Email
May 21, 2010
8:12 am
Hi Sam, Risk assessment: 1. Identify your assets (information, physical, software, people, service) 2. Identify threats to the assets Example: Laptop -...
517 Vikas Dhanker
dhankervikas Send Email
May 21, 2010
8:12 am
Hi First sugestion is Attend a Lead Auditor or Implementation course for ISO 27001. Thats the best way to understand the method. You shall follow the following...
518 ccna.haris Send Email May 24, 2010
7:49 am
Hi rufina, iam Hari Prasad ,new member to this group. i recently visited old messages & i find your below message is interesting. if possible Please post your...
519 samminchin Send Email May 26, 2010
7:23 am
Thanks! I've got as far as listing assets and threats to assets, however this brings me back to what the scope should be. As I mentioned, we're a small IT...
520 samminchin Send Email May 27, 2010
8:25 am
Hi Thanks for the pointers! Is it absolutely necessary to have attended a course? Obviously we'll have to do an internal audit further down the process, and I...
521 Eric Regalado
er_regalado Send Email
May 27, 2010
4:59 pm
Hi Sam, The person who will do the internal ISMS audit must be knowledgeable in: 1 how to do an internal audit according to ISO 19011 2 the requirements of...
522 Eric Regalado
er_regalado Send Email
May 30, 2010
5:19 pm
Dear Sam, Good day. You should write the scope first. Yes you can limit the scope to the processes and assets within the online backup part of the business....
Messages 493 - 522 of 591   Oldest  |  < Older  |  Newer >  |  Newest
Add to My Yahoo!      XML What's This?

Copyright © 2010 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines NEW - Help