How to Build an ISO 27001 SoA from Scratch - All You Need to Know

Поділитися
Вставка
  • Опубліковано 27 гру 2024

КОМЕНТАРІ • 21

  • @richarddayie1233
    @richarddayie1233 27 днів тому +1

    Your training is on point. I think you should do the same for Audit with the practical steps and sample datasets.

  • @dineshpinkcity1
    @dineshpinkcity1 29 днів тому

    Very informative and I really liked the structure of the content.

  • @DilipKumars-gz6sk
    @DilipKumars-gz6sk 25 днів тому

    yes ur videos are very practical and to the point

  • @vivekdhandha3919
    @vivekdhandha3919 11 днів тому

    Why is the slide at 16:25 min. position showing 27001:2013 control numbers
    A.12.2.1
    A.13.1.1
    A.18.1.1
    A.13.2.1

    • @PrabhNair1
      @PrabhNair1  11 днів тому

      It was just an reference i took

    • @vivekdhandha3919
      @vivekdhandha3919 11 днів тому +1

      @@PrabhNair1 But the reference must be from 27001:2022 as a complete session based on the newer version as well as the slide saying 93 controls and not 114

    • @PrabhNair1
      @PrabhNair1  11 днів тому

      @@vivekdhandha3919 in my previous consulting we have used this for gap assement for transition to iso 27001:13 to 22.Rest point you will see same

    • @PrabhNair1
      @PrabhNair1  10 днів тому

      @@vivekdhandha3919 goal of the video is to give transition view end to end and for legal required if old standard control can be used we can still use for conformity

  • @jithinsurendran678
    @jithinsurendran678 15 днів тому

    Perfect points man❤❤

  • @vinesh7665
    @vinesh7665 Місяць тому +2

    Hi prabh, Could you make a shorts or summary video. Which lists all the mandatory documents and also the best practice documents for ISO27001 for easy reference

  • @satyendrach3167
    @satyendrach3167 Місяць тому

    Crisp & Clear Video👌

  • @varinderpunjab479
    @varinderpunjab479 Місяць тому

    Thanks Prabh for the content ✌

  • @_M_M__S
    @_M_M__S 23 дні тому

    When should one prepare SoA, before the audit start or when all controls are discussed based on the risk rating/score

    • @PrabhNair1
      @PrabhNair1  11 днів тому

      It's can be done as per need

  • @Sambhav-y3h
    @Sambhav-y3h Місяць тому

    Hi Prabh, I have been following up your series this is a great learning
    However can you please let me know, if we are referring to ISO 27001:2022, where does Annex A category comes in play? In ISO 27001:2022, there exist 4 heads organizational, people, physical and Technological control, how do we go about other Annex A categories?

    • @PrabhNair1
      @PrabhNair1  Місяць тому

      @@Sambhav-y3h Annex A of ISO 27001 is a list of security controls that organizations can use to improve information security

  • @vinesh7665
    @vinesh7665 Місяць тому

    Is isms summary manual a mandatory document? or it is just a best practice

    • @PrabhNair1
      @PrabhNair1  Місяць тому

      @@vinesh7665 it's best practice

  • @vinesh7665
    @vinesh7665 Місяць тому

    For A.8.30 Outsourced development , as per the given case study the applicability of controls is No, but the reason for exclusion is " All software and applications used are sourced from third party vendors...". If softwares and applications are provided by third party vendors , shouldn't there be a Control for it like contact, patching etc. otherwise who and how the org is going to address the risk emerging from those application.

    • @PrabhNair1
      @PrabhNair1  Місяць тому +1

      @@vinesh7665 agree that is already covered in vendors management