<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISO 27001 advice in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/5981#M645</link>
    <description>&lt;P&gt;Hello Community, beginning planning stages to get an ISO 27001 cert. for my smallish healthcare software company.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering if I should attempt to do it myself, using a book, or a kit? Any advice on who's book or kit?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or should I just bite the bullet and hire a consultant? 1st estim. ~80K (good estim?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I seek to certify our application first, then the org, or just do both at once?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Little background, CISSP, CEH and limited info sec experience. 6 months at this job, been hardening infrastructure and doing policies. Already HIPAA compliant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Feb 2018 14:19:42 GMT</pubDate>
    <dc:creator>percussed</dc:creator>
    <dc:date>2018-02-02T14:19:42Z</dc:date>
    <item>
      <title>ISO 27001 advice</title>
      <link>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/5981#M645</link>
      <description>&lt;P&gt;Hello Community, beginning planning stages to get an ISO 27001 cert. for my smallish healthcare software company.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering if I should attempt to do it myself, using a book, or a kit? Any advice on who's book or kit?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or should I just bite the bullet and hire a consultant? 1st estim. ~80K (good estim?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I seek to certify our application first, then the org, or just do both at once?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Little background, CISSP, CEH and limited info sec experience. 6 months at this job, been hardening infrastructure and doing policies. Already HIPAA compliant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 14:19:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/5981#M645</guid>
      <dc:creator>percussed</dc:creator>
      <dc:date>2018-02-02T14:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISO 27001 advice</title>
      <link>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/5984#M646</link>
      <description>Why the ISO 27001 certification instead of seeking HITRUST certification? HITRUST is more prescriptive to healthcare and the CSF has a cross reference to ISO/IEC 27001, Joint Commission, HIPAA, NIST and even PCI. I think the certification is scalable to organization size as well. Just a thought.</description>
      <pubDate>Fri, 02 Feb 2018 15:15:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/5984#M646</guid>
      <dc:creator>dfcooktx</dc:creator>
      <dc:date>2018-02-02T15:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISO 27001 advice</title>
      <link>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/5986#M647</link>
      <description>&lt;P&gt;I agree with &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1353050705"&gt;@dfcooktx&lt;/a&gt;.&amp;nbsp; I work in the Healthcare IT space as well and used the HITRUST cross reference to ensure that I was complying with multiple frameworks.&amp;nbsp; We did have requirements to be compliant with ISO27002, etc. from our various customers so found it easier to go the HITRUST route.&amp;nbsp; In a previous role I worked in pharmaceutical IT and managed sites in Europe that required ISO27XXX certification and did use a consultant, ours ended up running a bit higher than the price you mentioned here, but it should not vary too much from that figure.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 15:59:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/5986#M647</guid>
      <dc:creator>jsjj01</dc:creator>
      <dc:date>2018-02-02T15:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISO 27001 advice</title>
      <link>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/5993#M648</link>
      <description>&lt;P&gt;First of all, confirm whether it's mandatory for your company to be certified, the benefits --- essentially compliance and marketing ---&amp;nbsp;and the costs involved, before you&amp;nbsp;take a decision.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a previous organization I was with, we went in for it at the organization level, and it was taken as a project, involving the creation and maintenance of the minimal documentation, the implementation / adoption of processes / procedures, training for a few staff, and so on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Limiting&amp;nbsp;the ISMS scope to&amp;nbsp;a single application --- assuming that's feasible --- may be tricky, given that auditors&amp;nbsp;tend to look at every little thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would suggest you ensure that your organization has the minimal set of documents they require, &amp;amp; proper controls / procedures running, before taking a shot at it. Doing it through a consultant may be advisable if you don't know about it --- but don't let that stop you from doing your own research.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could check the relevant pages of &lt;A href="https://advisera.com/27001academy/" target="_self"&gt;Adviseria&lt;/A&gt; for some more information on this...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 17:08:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/5993#M648</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2018-02-02T17:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISO 27001 advice</title>
      <link>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/6022#M649</link>
      <description>&lt;P&gt;Thanks so much!! I'll look into HITRUST.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 19:05:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/6022#M649</guid>
      <dc:creator>percussed</dc:creator>
      <dc:date>2018-02-02T19:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISO 27001 advice</title>
      <link>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/6074#M650</link>
      <description>&lt;P&gt;Thanks so much!! I'll look into the HITRUST crf. I've got a lot of footwork to do before we even approach certification.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 20:12:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/ISO-27001-advice/m-p/6074#M650</guid>
      <dc:creator>percussed</dc:creator>
      <dc:date>2018-02-02T20:12:56Z</dc:date>
    </item>
  </channel>
</rss>

