<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>ISO 27001 &amp; BS 25999 Blog - Latest Comments</title><link xmlns="http://www.w3.org/2005/Atom" rel="http://api.friendfeed.com/2008/03#sup" href="http://disqus.com/sup/all.sup#forumcomments-49bf4500" type="application/json"/><link>http://iso27001standard.disqus.com/</link><description></description><atom:link href="http://iso27001standard.disqus.com/comments.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Wed, 09 May 2012 13:19:21 -0000</lastBuildDate><item><title>Re: Top 10 information security blogs</title><link>http://blog.iso27001standard.com/2012/05/07/top-10-information-security-blogs/#comment-524600771</link><description>&lt;p&gt;Cryptex, no?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">lector amigo</dc:creator><pubDate>Wed, 09 May 2012 13:19:21 -0000</pubDate></item><item><title>Re: The importance of Statement of Applicability for ISO 27001</title><link>http://blog.iso27001standard.com/2011/04/18/the-importance-of-statement-of-applicability-for-iso-27001/#comment-506642982</link><description>&lt;p&gt;Nice and informative post&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Abcdefghijk</dc:creator><pubDate>Mon, 23 Apr 2012 05:09:36 -0000</pubDate></item><item><title>Re: ¿Cuánto cuesta la implementación de la norma ISO 27001?</title><link>http://blog.iso27001standard.com/es/2011/02/08/%c2%bfcuanto-cuesta-la-implementacion-de-la-norma-iso-27001/#comment-498992969</link><description>&lt;p&gt;It is important what you mention in the blog, since your experience directs his that newly we begin in this experience of implementation of ISO 27001. In the possible and low thing your valued time, you agradeceria support me as teacher and guide, in a safety project of the information that I come initiating for a state entity. &lt;/p&gt;

&lt;p&gt;Regards from Lima - Peru&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jos Mar Mercado</dc:creator><pubDate>Mon, 16 Apr 2012 12:32:43 -0000</pubDate></item><item><title>Re: ¿Cuánto cuesta la implementación de la norma ISO 27001?</title><link>http://blog.iso27001standard.com/es/2011/02/08/%c2%bfcuanto-cuesta-la-implementacion-de-la-norma-iso-27001/#comment-498991488</link><description>&lt;p&gt;Es importante lo que mencionas en el blog, ya que tu experiencia nos encamina a los que recien empezamos en esta experiencia de implementacion de la ISO 27001. En lo posible y bajo tu preciado tiempo, te agradeceria me apoyes como maestro y guia, en un proyecto de seguridad de la informacion que vengo iniciando para una entidad estatal. &lt;/p&gt;

&lt;p&gt;Saludos desde Lima - Peru&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jose Maria Mercado Chirito</dc:creator><pubDate>Mon, 16 Apr 2012 12:30:37 -0000</pubDate></item><item><title>Re: How to become ISO 27001 Lead Auditor</title><link>http://blog.iso27001standard.com/2012/02/27/how-to-become-iso-27001-lead-auditor/#comment-484308278</link><description>&lt;p&gt;Bilal,&lt;/p&gt;

&lt;p&gt;There are several issues you would need to concetrate on, but I would say these are the ones that cause the most of the failures at the exam:&lt;br&gt;1) Finding the way in the standard&lt;br&gt;2) Assumptions&lt;br&gt;3) What does and what doesn’t have to be documented&lt;br&gt;4) Writing the finding statement&lt;/p&gt;

&lt;p&gt;For more details please look at my webinar ISO 27001 Lead Auditor Course preparation training &lt;a href="http://www.iso27001standard.com/en/webinars/ISO-27001-Lead-Auditor-Course-preparation-training" rel="nofollow"&gt;http://www.iso27001standard.co...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dejan Kosutic</dc:creator><pubDate>Tue, 03 Apr 2012 05:06:35 -0000</pubDate></item><item><title>Re: How to become ISO 27001 Lead Auditor</title><link>http://blog.iso27001standard.com/2012/02/27/how-to-become-iso-27001-lead-auditor/#comment-483656122</link><description>&lt;p&gt;Hi Dejan,&lt;br&gt;I am apprearing for the Lead Auditor  exam. Please suggest me what part of the course should i concentrate more so that i will pass the exam. Your suggestion will be helpful&lt;br&gt;Thanks&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bilal Shafahat</dc:creator><pubDate>Mon, 02 Apr 2012 12:34:57 -0000</pubDate></item><item><title>Re: La importancia de la Declaración de aplicabilidad para la norma ISO 27001</title><link>http://blog.iso27001standard.com/es/2011/04/18/la-importancia-de-la-declaracion-de-aplicabilidad-para-la-norma-iso-27001/#comment-482675249</link><description>&lt;p&gt;Joel,&lt;/p&gt;

&lt;p&gt;If I understood well, you are asking what would be the reasons for updating the policy and the Statement of Applicability. The reasons for changing the policy would be that the security objectives have changed, or that the security process has changed; the reasons for changing the SoA would be changed control objectives, or different way of implementing certain control.&lt;/p&gt;

&lt;p&gt;Dejan&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dejan Kosutic</dc:creator><pubDate>Sun, 01 Apr 2012 05:16:41 -0000</pubDate></item><item><title>Re: La importancia de la Declaración de aplicabilidad para la norma ISO 27001</title><link>http://blog.iso27001standard.com/es/2011/04/18/la-importancia-de-la-declaracion-de-aplicabilidad-para-la-norma-iso-27001/#comment-480763611</link><description>&lt;p&gt;Hola Dejan.&lt;/p&gt;

&lt;p&gt;Al aplicar el ciclo de Deming, la consulta sería:&lt;br&gt;Sobre un mismo proceso donde se implemento el SGSI ¿Cuáles serían las razones para actualizar las políticas y la declaración de aplicabilidad?&lt;br&gt;Gracias.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joel Mercado</dc:creator><pubDate>Fri, 30 Mar 2012 09:55:30 -0000</pubDate></item><item><title>Re: How to become ISO 27001 Lead Auditor</title><link>http://blog.iso27001standard.com/2012/02/27/how-to-become-iso-27001-lead-auditor/#comment-475709579</link><description>&lt;p&gt;Dear Mr. Dejan&lt;/p&gt;

&lt;p&gt;I'm very happy by reading this "How to become ISO 27001 Lead Auditor", it has helped me lots in order to take decision how much time it would take to be ISO 27001 lead auditor. Thank you very much for putting this information in very simple and straight manner. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Darshna</dc:creator><pubDate>Sun, 25 Mar 2012 04:00:23 -0000</pubDate></item><item><title>Re: Lessons learned from ISO 27001 implementation</title><link>http://blog.iso27001standard.com/2012/03/12/lessons-learned-from-iso-27001-implementation/#comment-464053534</link><description>&lt;p&gt;In my opinion, there are 2 good reasons why you need to pay for ISO 27001 documentation:&lt;/p&gt;

&lt;p&gt;1) If you want to implement ISO 27001, you need to make an investment - if nothing else, your employees will have to spend quite a lot of time. Since you will need to invest, you have to figure out how to decrease the level of investment - good documentation templates will save you considerable amount of time.&lt;/p&gt;

&lt;p&gt;2) Actually you can find some free documentation templates on the Internet. But the problem with those free documents is that they are not comprehensive, and they won't cover everything required by the standard. On the other hand, we have invested quite an effort in developing the Documentation Toolkit which covers everything you need - and yes, it is not free.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dejan Kosutic</dc:creator><pubDate>Tue, 13 Mar 2012 03:55:36 -0000</pubDate></item><item><title>Re: Lessons learned from ISO 27001 implementation</title><link>http://blog.iso27001standard.com/2012/03/12/lessons-learned-from-iso-27001-implementation/#comment-463555889</link><description>&lt;p&gt;But how/where can one actually get one's hands on the ISO27000 standards documents? I've been looking all over and it appears that they are pay-only which is rather unfortunate for a security standard as that ensures a lot of people won't implement it (even partially) simply because they can't get their hands on it.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Treed-iso27001standard Com</dc:creator><pubDate>Mon, 12 Mar 2012 14:30:13 -0000</pubDate></item><item><title>Re: Using ISO 9001 for implementing ISO 27001</title><link>http://blog.iso27001standard.com/2010/03/08/using-iso-9001-for-implementing-iso-27001/#comment-458856815</link><description>&lt;p&gt;Dear Dejan &lt;/p&gt;

&lt;p&gt;this is really important. It's admired that most of the professional don't think about this aspect of the security&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Manendra Liyanage</dc:creator><pubDate>Wed, 07 Mar 2012 11:03:22 -0000</pubDate></item><item><title>Re: Lista de verificação para implementação da ISO 27001</title><link>http://blog.iso27001standard.com/pt-br/2010/12/21/lista-de-verificacao-para-implementacao-da-iso-27001/#comment-449215441</link><description>&lt;p&gt;Muito Bom.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Paulo</dc:creator><pubDate>Sun, 26 Feb 2012 07:33:28 -0000</pubDate></item><item><title>Re: Mandatory documented procedures required by ISO 27001</title><link>http://blog.iso27001standard.com/2010/05/04/mandatory-documented-procedures-required-by-iso-27001/#comment-447744831</link><description>&lt;p&gt;&lt;br&gt;you have a very creative and very interesting post, i just bookmark your page.&lt;br&gt;will also tell my close friend to ready this and maybe also spread your post in the &lt;br&gt;social network. very excellent !! &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">sbobet </dc:creator><pubDate>Fri, 24 Feb 2012 05:34:00 -0000</pubDate></item><item><title>Re: ISO 27001 risk assessment &amp;#038; treatment – 6 basic steps</title><link>http://blog.iso27001standard.com/2011/11/22/iso-27001-risk-assessment-treatment-%e2%80%93-6-basic-steps/#comment-444054995</link><description>&lt;p&gt;Hi - thanks for the reply. There are plenty of examples of "Best Practice" though - ISO27002, PCIDSS, CIS standards, the Grunschutz manual.&lt;/p&gt;

&lt;p&gt;I have started a thread at the ISO27001security google group, will be interesting to see the discussion there.&lt;/p&gt;

&lt;p&gt;Regards&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joe W</dc:creator><pubDate>Mon, 20 Feb 2012 10:33:06 -0000</pubDate></item><item><title>Re: ISO 27001 risk assessment &amp;#038; treatment – 6 basic steps</title><link>http://blog.iso27001standard.com/2011/11/22/iso-27001-risk-assessment-treatment-%e2%80%93-6-basic-steps/#comment-441815138</link><description>&lt;p&gt;I agree IT Grundschutz is a bit too much - when you perform the normal risk assessment according to ISO 27001, it takes somewhere between 1 and 3 months, depending on the size of the company.&lt;/p&gt;

&lt;p&gt;To answer your question - if you followed only the "best practice" (if such thing really exists) and common sense, chances are you are going to miss something important. In my experience, the clients I've worked with are aware only of only 40 to 50% of risks, therefore initially didn't plan for controls to mitigate such risks.&lt;/p&gt;

&lt;p&gt;Yes - risk assessment takes time. But if you do it properly, you'll discover a lot of things you weren't aware, and only then you will realize it was an investment that was worth it.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dejan Kosutic</dc:creator><pubDate>Fri, 17 Feb 2012 07:45:28 -0000</pubDate></item><item><title>Re: ISO 27001 risk assessment &amp;#038; treatment – 6 basic steps</title><link>http://blog.iso27001standard.com/2011/11/22/iso-27001-risk-assessment-treatment-%e2%80%93-6-basic-steps/#comment-441802548</link><description>&lt;p&gt;I am struggling to understand the benefit of following a formal risk assessment methodology, relative to its cost.&lt;/p&gt;

&lt;p&gt;If you catalog all your information assets, the vulnerabilities of each, and the threat agents which might exploit those vulnerabilities, and assess the impact and likelihood of each risk actually happening, and mapping them to security controls ... you would spend days or weeks creating an enormous document which I suspect no one (apart from the ISO27001 auditor) would ever read!&lt;/p&gt;

&lt;p&gt;For example I had a look at the Grundschutz manual which is about 3000 pages long! It lists about 400 "threats" (doesn't seem to separate "vulnerabilities" and "threat agents").&lt;/p&gt;

&lt;p&gt;In practice the fact that we have any particular security control (such as using anti-virus software and making sure it is up to date) is because it's common sense, best practice, everyone does it and everyone (your customers etc.) expects you to do it.&lt;/p&gt;

&lt;p&gt;Perhaps I am  missing something?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joe W</dc:creator><pubDate>Fri, 17 Feb 2012 07:13:51 -0000</pubDate></item><item><title>Re: How long does it take to implement ISO 27001 / BS 25999?</title><link>http://blog.iso27001standard.com/2011/11/08/how-long-does-it-take-to-implement-iso-27001-bs-25999/#comment-432343716</link><description>&lt;p&gt;Good post.  27001/2 are in need of major facelift.  Hopefully this facelift can enable more adoption in US.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Fred Scholl</dc:creator><pubDate>Tue, 07 Feb 2012 16:57:51 -0000</pubDate></item><item><title>Re: Risk assessment tips for smaller companies</title><link>http://blog.iso27001standard.com/2010/02/22/risk-assessment-tips-for-smaller-companies/#comment-428620222</link><description>&lt;p&gt;Sean,&lt;/p&gt;

&lt;p&gt;Here you can see our threats &amp;amp; vulnerabilities catalogue: &lt;a href="http://wiki.iso27001standard.com/index.php?title=Threats_%26_vulnerabilities" rel="nofollow"&gt;http://wiki.iso27001standard.c...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dejan Kosutic</dc:creator><pubDate>Fri, 03 Feb 2012 10:14:23 -0000</pubDate></item><item><title>Re: Risk assessment tips for smaller companies</title><link>http://blog.iso27001standard.com/2010/02/22/risk-assessment-tips-for-smaller-companies/#comment-428561238</link><description>&lt;p&gt;Where can i get a threats and vulnarabilites catalogue?&lt;br&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Sean Facer</dc:creator><pubDate>Fri, 03 Feb 2012 08:54:50 -0000</pubDate></item><item><title>Re: What is the difference between Recovery Time Objective (RTO) and Recovery Point Objective (RPO)?</title><link>http://blog.iso27001standard.com/2012/01/30/what-is-the-difference-between-recovery-time-objective-rto-and-recovery-point-objective-rpo/#comment-427707416</link><description>&lt;p&gt;One of the best, most concise explanations of RTO / RPO I've seen in a long time!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Stevelewis1</dc:creator><pubDate>Thu, 02 Feb 2012 08:45:13 -0000</pubDate></item><item><title>Re: Document management in ISO 27001 &amp;#038; BS 25999-2</title><link>http://blog.iso27001standard.com/2010/03/30/document-management-within-iso-27001-bs-25999-2/#comment-417515414</link><description>&lt;p&gt;Great post&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Footinheaven</dc:creator><pubDate>Sat, 21 Jan 2012 12:43:44 -0000</pubDate></item><item><title>Re: How much does ISO 27001 implementation cost?</title><link>http://blog.iso27001standard.com/2011/02/08/how-much-does-iso-27001-implementation-cost/#comment-417314966</link><description>&lt;p&gt;Rich,&lt;/p&gt;

&lt;p&gt;Costs of the certification body for 50-employee company - the certification would take between 7 and 10 auditor man/days. The costs of the man/day vary from country to country, from US$ 500 to US$ 2000, so you would have to find out what is applicable for your country.&lt;/p&gt;

&lt;p&gt;Other costs (consulting, training) vary even more - if the company has the employees with all the knowledge, they wouldn't have to spend much on it. If they need such services, the prices on the market are very different - if they buy it from our Information Security &amp;amp; Business Continuity Academy, the training (via webinars) would cost appx. US$ 1000 annually for one person, and ca US$ 5000 for documentation/mentoring/consulting services. &lt;br&gt;Dejan&lt;/p&gt;

&lt;p&gt;[image: DISQUS] &amp;lt;http: disqus.com=""&amp;gt;&amp;lt;/http:&amp;gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dejan Kosutic</dc:creator><pubDate>Sat, 21 Jan 2012 04:15:17 -0000</pubDate></item><item><title>Re: How much does ISO 27001 implementation cost?</title><link>http://blog.iso27001standard.com/2011/02/08/how-much-does-iso-27001-implementation-cost/#comment-416585660</link><description>&lt;p&gt;Hi - I'm a graduate student working on a case study that involves ISO27001/17799 certification.  I was hoping that I could ask you a favour.  I know it is not possible to provide an accurate estimate of the cost of certification but I'm hoping that you can give me a ballpark, rough estimate.  It would be a great help to have an estimate from someone who actually understands the process!&lt;/p&gt;

&lt;p&gt;Our fictional company has about 50 employees and sells a secure, web-based document management system that does about 3 million dollars in business.  I have already recommended the creation of an information security officer but I would like a rough cost for:&lt;br&gt;training &lt;br&gt;consulting &lt;br&gt;certification &lt;/p&gt;

&lt;p&gt;Once again, this is a fictional company and your quote will only be used in a paper in our course and will never come back to haunt you but it will help us to get a better mark by showing that we've actually contacted experts in the field to help us to shape our plan!&lt;/p&gt;

&lt;p&gt;Thanks for any information you can give me!&lt;br&gt;Rich.&lt;br&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Richsmi01</dc:creator><pubDate>Fri, 20 Jan 2012 09:22:32 -0000</pubDate></item><item><title>Re: Problemas para definir el alcance de la norma ISO 27001</title><link>http://blog.iso27001standard.com/es/2010/06/29/problemas-para-definir-el-alcance-de-la-norma-iso-27001/#comment-413447224</link><description>&lt;p&gt;Hola soy estudiante y pues estoy limitando el alcance solo para el departamento de TI, pero de hai que hago como especifico de manaera detallada....ayuda estoy confundidididsisisima&lt;br&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">taniavero</dc:creator><pubDate>Tue, 17 Jan 2012 10:58:48 -0000</pubDate></item></channel></rss>
