ISO 17799/27001 Frequently Asked Questions
1) Have there been any recent developments with respect to ISO 27000 Standards?
Yes. A standard specific ro security risk management has been published, ISO 27005 (www.standards.bz/iso-27005.html). However, it should be noted that there are a number of other standards also being developed in this area, including ISO 31000 and BS 31100, and it is currently unclear how these will relate, if at all.
2) Can I discuss the standards with other people online?
Yes. The two biggest forums are:
Yahoo: 17799 and 27001 Security
ISO 27001 and ISO 27002 Community Portal
3) Who wrote the standards?
Originally a BSI committee, which included representatives from a wide section of commerce/industry. It was subsequently reviewed by an ISO committee and emerged through their publication process.
4) Can I republish articles from the ISO 27000 Newsletter internally, or even on our external internet site?
Yes, subject to a link to our website.
5) How do I become a certified auditor?
IRCA, the International Register for Certified Auditors (http://www.irca.org) operates a certification scheme for ISMS audit.
source: ccure.org and molemag.net
CompliancesForum provide FREE template, checklist, and update for your Regulatory Compliance need: Basel II Accord, Gramm Leach Bliley (GLBA), Healthcare Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standards (PCI DSS), Sarbanes Oxley Act (SOA)






