Search the web
Sign In
New User? Sign Up
iso-27001 · ISO 27001
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Hear how Yahoo! Groups has changed the lives of others. Take me there.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 95 - 125 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
95
Hi all, I have couple of questions: Has anyone worked on a Non-conformity report? Do you have any approach on how to perform ISO test, Sampling methdology,...
Jesus Benitez
jbenitez00
Offline Send Email
Jul 19, 2006
6:10 pm
96
Dear Jesus, Please tell whether you are talking about raising a Non-Conformity (NC) or describing action against a rasied NC? If you're thinking of raising an...
Engr. Syed Kashif Ali...
skaat2000
Online Now Send Email
Jul 20, 2006
6:18 am
97
Kashif thank you very much for taking your time to response to my e-mail. I will clarify myself in my questions: Has anyone worked on a Non-conformity report? ...
Jesus Benitez
jbenitez00
Offline Send Email
Jul 21, 2006
6:20 am
98
Hi All, Till these days I have been a reader of this group, but never wrote to this group on any of the issues or problems. Sorry for that ... you should be...
gijo varghese
gijo_varghese
Offline Send Email
Jul 24, 2006
8:43 pm
99
Hi Gijo, ... My opinion is that effectiveness can't be measured as some information is alwasy missing. Let's say a control say that no equipment must be ...
Vicente Aceituno
aceituno
Offline Send Email
Jul 25, 2006
6:19 am
100
Does anyone has detail information about the Six Stages of the ISO 27001 preparation process? or tell me where can I find such information. Thanks, Jesus...
jbenitez00
Offline Send Email
Aug 2, 2006
2:20 pm
101
Hello All, I have a question regarding the ISO-27701 assessment. If during the assessment we as auditor identify an un-conformity, do we have to provide...
jbenitez00
Offline Send Email
Aug 10, 2006
7:53 pm
103
Dear Jesus, An auditor shouldn't provide any solution, only note what has been observed and determine compliance or non-compliance. This is for two reasons: 1)...
Uriel Doryen
udoryen
Offline Send Email
Aug 10, 2006
10:06 pm
104
Hi Jesus, It actually depends how you are conducting an audit (I mean as an Internal Auditor or as a consultant). If you are auditing the process as an...
Arindam.Banerjee
Arindam.Banerjee@...
Send Email
Aug 11, 2006
7:12 am
105
Recommendations should not be provided.. How can an auditor take the same role as a consultant and then come back in the next audit and verify his own...
abhishek
abhishek110016
Offline Send Email
Aug 11, 2006
7:12 am
106
Hi I had the "chance" to read both books... I think they really do not reflect the "core or spirit" of what one could need for ISO 27001... Just talking about...
Sa SA
fairysamy
Offline Send Email
Aug 11, 2006
7:16 am
107
Yes Arindam, your opinion is correct. As an external auditor during 3rd party audit you should not give any solution regarding your non conformity, although...
Pendar
pendarv
Offline Send Email
Aug 11, 2006
9:20 pm
108
It also depends are you acting as an assessment or an audit? If just an assessment I highly recommend providing a solution, thats what you are getting...
Carter Schoenberg
carterschoen...
Offline Send Email
Aug 11, 2006
9:23 pm
109
Hi all. I am new to this list, so thought I would introduce myself. I manage Information Services for a State Government Agency in Sydney,Australia. Our State...
lyndons@...
lyndonsharp
Offline Send Email
Aug 13, 2006
8:26 pm
110
Since you've passed one audit, you have a foundation for doing a gap analysis for your other units. I would pick the next area you'd like to certify, and do a...
cstopfo@...
cstopfo
Offline Send Email
Aug 14, 2006
6:12 am
111
Dear All, I would like to have some insight on how to conduct audit at the project level (in software development and BPO industry). As most of the controls of...
Arindam.Banerjee
Arindam.Banerjee@...
Send Email
Aug 14, 2006
6:12 am
112
"Adequate back-up facilities should be provided to ensure that all essential information and software can be recovered following a disaster or media failure"...
Vicente Aceituno
aceituno
Offline Send Email
Aug 25, 2006
5:40 pm
113
Think Disaster Recovery and Business Continuity. A Hot or Cold site that is physically separate from your production site. Thanks, Kim Sassaman, CISSP ...
Kim Sassaman
ksassaman3
Offline Send Email
Aug 25, 2006
6:42 pm
114
It just tells you that you should have a back-up mechanism in place, for speedy and effective recovery at the time of disaster. The back-up should never be...
Arindam.Banerjee
Arindam.Banerjee@...
Send Email
Aug 25, 2006
6:43 pm
115
Dear Friends, Our external auditors have put an observation that our ISMS Objectives need to be re-defined to be SMART, as presently they are too generalistic....
Sarat Kurra
saisaratk
Offline Send Email
Sep 15, 2006
7:32 pm
116
Dear Sarat, ... I think you will need ISM3 (www.ism3.com) to enhance your ISO27001 ISMS. ... A security objectices / security targets example from ISM3 is: ...
Vicente Aceituno
aceituno
Offline Send Email
Sep 18, 2006
11:31 am
117
refrence to your query, the opinion is as below: S - Specific--- means is to identify the key/target area for implemenatation of ISO M - Measurable----means is...
rana happy
avithakur2000
Offline Send Email
Sep 18, 2006
11:37 am
118
The latest issue has just arrived. For anyone who doesn't receive it, the full copy is below: ______________________________________________________ THE ISO...
iso17799standard
iso17799stan...
Offline Send Email
Sep 26, 2006
10:31 pm
119
Hi all I work for a commercial company and the head of Info Sec is an ex- military man. The company wants to achieve certification in the standard. Most of the...
BDSM Spank
triathlonman...
Offline Send Email
Oct 13, 2006
7:32 am
120
Hi JP, It's a common dillema. The head of Info Sec must understand that there are no mandatory controls. However, there are baselines. I suggest that you...
Rainier Vergara
rainvergara
Offline Send Email
Oct 13, 2006
8:34 pm
121
Hi, I'm an ISO 27001:2005 certified LA and LI ....Well if you ask me, there is a need to conduct Risk Assessment before since it will throw out the gap between...
Dhananjaya Naronikar
djisms
Offline Send Email
Oct 13, 2006
8:41 pm
122
Hi, Having done eight implementations for clients, both are right and otherwise. My experience with Auditors have been is that they are very cautious about the...
Mayank Bhardwaj
decaharry
Offline Send Email
Oct 14, 2006
8:15 pm
123
Hi, A week ago, I finished my eight implementation; whichwas certified. So far, I have conducted more than a dozen implementation courses; on behalf of BSI...
Mayank Bhardwaj
decaharry
Offline Send Email
Oct 14, 2006
8:23 pm
124
Hi JP, I think in corporate we are all working in a commercial concern. Anyway, if you look at the methodology of ISMS or ISO 27001,the methodology is -...
saisaratk
Offline Send Email
Oct 16, 2006
8:16 am
125
I'm in complete agreement with Dhananjay. It make sense to understand the applicability of Control Objectives before in order to ensure that Objectives are...
Raj
raj2610
Offline Send Email
Oct 16, 2006
8:20 am
Messages 95 - 125 of 451   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help