Search alphaZ documents
Products meeting the search criteria
Powerpoint Presentation providing an overview of the ISO 27001:2022 standard. Presentation covers;History of ISO 27001Overview of the ISO 27001 standardClauses 1,2 & 3Clause 4 Context of the ..
This file provides in detail, the list of mandatory documents which must be in place for an organisation to be ISO 27001:2022 compliant. The document is formatted in a way which allows for an aud..
I use this toolkit with my clients to set up integrated ISO 9001, ISO 14001, ISO 45001 and ISO 27001 management systems. The integrated structure means the InfoSec controls sit alongside the other man..
I use this toolkit with my clients to set up integrated ISO 9001, ISO 14001, ISO 45001, ISO 27001 and ISO 22301 management systems. The InfoSec and business continuity controls sit alongside the wider..
This toolkit provides a simple and easy to use, fully integrated, management system covering 6 standards!
Logo Update Service *
..
This register is the first section of the Document register which can be used to list Key Company Records.Simple table format for detailing;1. Type of Record2. Description 3. Where stored / Security4...
Training talk on Integrated Management Systems (IMS) and including the General Guidance document GG-1-09 Integrated Management System (IMS)Talk Description;• Overview of the Integrated Management..
Training talk (prepared using F-Q7-Training_Talk_Attendance) on Business Continuity and referencing the General Guidance document GG-1-10 Internal Audits.Talk Description;• Definition of an inter..
Training talk (prepared using F-Q7-Training_Talk_Attendance) on Business Continuity and referencing the General Guidance document GG-1-11 Management Review and Objectives.Talk Description;• Overv..
Training talk on ISO Standards and ISO Certification and referencing the General Guidance document GG-1-12 ISO Standards and ISO Certification. Talk Description;• Overview of common ISO..
Training talk on Data Protection and includes the General Guidance document GG-1-16 Data ProtectionTalk Description;• Definition of data protection • Compliance • Personal informat..
Training talk on General Information Security and including GG-8-01 Information Security General.Talk Description;• General Information Security – guidance, employee responsibilities• D..
Training talk on Data Backup and including the General Guidance document - GG-8-02 Data Backup.Talk Description;• Guidance for workers on data backup requirements to maintain information sec..
Training talk on Software and Malware and including the General Guidance document - GG-8-03 Software and Malware.Talk Description;• Guidance on the use and installation of software to maintain in..
Training talk on Access Control and User Authentication and including the General Guidance document - GG-8-04 Access Control and User Authentication.Talk Description;• Guidance on control o..
Training talk on Secure Project Management and Outsourcing and including the General Guidance document - GG-8-05 Secure Project Management and Outsourcing.Talk Description;• Guida..
Training talk on Secure Project Management and Outsourcing and including the General Guidance document - GG-8-06 Information TransferTalk Description;• Guidance on the secure transfer ..
Training talk on Information Classification and Protection and including the General Guidance document - GG-8-07 Information Classification and ProtectionTalk Description;• Guidance on the ..
Training talk on Managing Users and including the General Guidance document - GG-8-08 Managing UsersTalk Description;• Guidance on managing user accounts –new starters, leavers and change o..
When I audit information security, an asset inventory is the foundation - what information you hold, who owns it and how it is protected. This matrix captures that in one view, so the controls have so..
For data protection you have to know what personal data you hold, where it sits, who can see it and how it is protected. This matrix maps that out, and it is the first thing worth having when someone ..
For staff leaving your business, this form allows you to record that relevant checks have taken place: equipment returned, key/logins de-activated, and comments/feedback can be captured from the depar..
This form allows you to complete a data transfer and processing agreement, detailing the data transferred/processed and a declaration from the data processor, with confirmation from the data protectio..
For monitoring overall IT systems - this form allows you to check: backup systems, network, physical security, computers, handheld devices and information security risks.
Effective Form Tem..
This is a comprehensive risk assessment template for capturing general risks which can arise in a business, including the risk, inherent risk rating, controls applied and residual risk rating. Icons c..
Under the UK GDPR, anyone whose personal data you hold can ask to see it, and you normally have one month to respond. This form works a request through in three stages - logging what was asked for, re..
When personal data is lost, disclosed or accessed without authority, the UK GDPR gives you a short window to act. This form logs the breach, the containment action, the review of cause and whether it ..