<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ISO 27001 &#38; ISO 22301</title>
	<atom:link href="http://blog.iso27001standard.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.iso27001standard.com</link>
	<description>Leading blog on ISO 27001 &#38; ISO 22301. Author: Dejan Kosutic</description>
	<lastBuildDate>Tue, 18 Jun 2013 06:34:11 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>One Information Security Policy, or several policies?</title>
		<link>http://blog.iso27001standard.com/2013/06/18/one-information-security-policy-or-several-policies/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=one-information-security-policy-or-several-policies</link>
		<comments>http://blog.iso27001standard.com/2013/06/18/one-information-security-policy-or-several-policies/#comments</comments>
		<pubDate>Tue, 18 Jun 2013 06:34:11 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[information security policy]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[ISO 27001]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=2293</guid>
		<description><![CDATA[Very often I see questions on various forums on how to develop an Information Security Policy. Quite frankly, I don&#8217;t think it is a good idea to stuff all the security rules into a single document, and here&#8217;s why&#8230; Information security policy vs. ISMS Policy First of all, let&#8217;s clarify the difference between these two [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2013/06/18/one-information-security-policy-or-several-policies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The purpose of Business continuity policy according to ISO 22301</title>
		<link>http://blog.iso27001standard.com/2013/06/04/the-purpose-of-business-continuity-policy-according-to-iso-22301/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-purpose-of-business-continuity-policy-according-to-iso-22301</link>
		<comments>http://blog.iso27001standard.com/2013/06/04/the-purpose-of-business-continuity-policy-according-to-iso-22301/#comments</comments>
		<pubDate>Tue, 04 Jun 2013 11:24:51 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[BCMS]]></category>
		<category><![CDATA[Business continuity]]></category>
		<category><![CDATA[Business continuity policy]]></category>
		<category><![CDATA[ISO 22301]]></category>
		<category><![CDATA[security objectives]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=2285</guid>
		<description><![CDATA[Why would you need a Policy once you have Business impact analysis, Business continuity strategy and Business continuity plan? This is probably a question many experienced business continuity/disaster recovery practitioners are asking themselves, so here&#8217;s why ISO 22301 (a leading business continuity management standard) says it’s mandatory. Main purpose The main purpose of Business continuity [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2013/06/04/the-purpose-of-business-continuity-policy-according-to-iso-22301/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO 22301 vs. ISO 22313</title>
		<link>http://blog.iso27001standard.com/2013/05/21/iso-22301-vs-iso-22313/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=iso-22301-vs-iso-22313</link>
		<comments>http://blog.iso27001standard.com/2013/05/21/iso-22301-vs-iso-22313/#comments</comments>
		<pubDate>Tue, 21 May 2013 20:41:01 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[BCMS]]></category>
		<category><![CDATA[ISO 22301]]></category>
		<category><![CDATA[ISO 22313]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=2277</guid>
		<description><![CDATA[I was quite skeptical when I started to read ISO 22313, the guidance standard on business continuity management, but I was proved to be wrong. It can be quite useful as a supplement to ISO 22301 – here&#8217;s what I found: Similarities and differences If you are familiar with ISO 27001 and ISO 27002 (see [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2013/05/21/iso-22301-vs-iso-22313/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Backup policy – How to determine backup frequency</title>
		<link>http://blog.iso27001standard.com/2013/05/07/backup-policy-how-to-determine-backup-frequency/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=backup-policy-how-to-determine-backup-frequency</link>
		<comments>http://blog.iso27001standard.com/2013/05/07/backup-policy-how-to-determine-backup-frequency/#comments</comments>
		<pubDate>Tue, 07 May 2013 13:20:21 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[business impact analysis]]></category>
		<category><![CDATA[ISO 22301]]></category>
		<category><![CDATA[maximum data loss]]></category>
		<category><![CDATA[recovery point objective]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=2269</guid>
		<description><![CDATA[Did you think that the frequency of backup is based on the IT manager&#8217;s whims? Or, perhaps, based on the least expensive solution? Well, you are wrong. Backup policy, or to be precise – the most important part of this policy – how often the backup is to be performed, must be based on analysis. [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2013/05/07/backup-policy-how-to-determine-backup-frequency/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO 27001 project – How to make it work</title>
		<link>http://blog.iso27001standard.com/2013/04/22/iso-27001-project-how-to-make-it-work/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=iso-27001-project-how-to-make-it-work</link>
		<comments>http://blog.iso27001standard.com/2013/04/22/iso-27001-project-how-to-make-it-work/#comments</comments>
		<pubDate>Mon, 22 Apr 2013 20:13:02 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[Project planning]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=2258</guid>
		<description><![CDATA[Many companies don&#8217;t realize this, but setting the ISO 27001 project properly at the beginning of the implementation is one of the most important elements if you want to implement ISMS in an acceptable time and budget. Don&#8217;t try this without management support Management commitment must come before anything else – if your top executives [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2013/04/22/iso-27001-project-how-to-make-it-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>List of mandatory documents required by ISO 27001</title>
		<link>http://blog.iso27001standard.com/2013/04/09/list-of-mandatory-documents-required-by-iso-27001/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=list-of-mandatory-documents-required-by-iso-27001</link>
		<comments>http://blog.iso27001standard.com/2013/04/09/list-of-mandatory-documents-required-by-iso-27001/#comments</comments>
		<pubDate>Tue, 09 Apr 2013 11:20:05 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[document management]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[mandatory procedures]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=2251</guid>
		<description><![CDATA[It&#8217;s actually funny, but it is rather difficult to find a list of all mandatory documents required by ISO 27001 anywhere on the Internet – this problem came to my attention when one of the readers of my blog told me he had to read several of my articles to assemble this list. Anyway, a [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2013/04/09/list-of-mandatory-documents-required-by-iso-27001/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>5 criteria for choosing an ISO 22301 / ISO 27001 consultant</title>
		<link>http://blog.iso27001standard.com/2013/03/25/5-criteria-for-choosing-a-iso-22301-iso-27001-consultant/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=5-criteria-for-choosing-a-iso-22301-iso-27001-consultant</link>
		<comments>http://blog.iso27001standard.com/2013/03/25/5-criteria-for-choosing-a-iso-22301-iso-27001-consultant/#comments</comments>
		<pubDate>Mon, 25 Mar 2013 15:34:18 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[consulting]]></category>
		<category><![CDATA[ISO 22301]]></category>
		<category><![CDATA[ISO 27001]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=2235</guid>
		<description><![CDATA[If you&#8217;re implementing ISO 27001 or ISO 22301 for the first time, you&#8217;re probably considering hiring a consultant to help you. But, which consultant should you hire, what are the potential problems, and how much should you pay? The purpose of an ISO 22301/ISO 27001 consultant A consultant should shorten your implementation time – he [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2013/03/25/5-criteria-for-choosing-a-iso-22301-iso-27001-consultant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can ISO 27001 risk assessment be used for ISO 22301?</title>
		<link>http://blog.iso27001standard.com/2013/03/11/can-iso-27001-risk-assessment-be-used-for-iso-22301/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=can-iso-27001-risk-assessment-be-used-for-iso-22301</link>
		<comments>http://blog.iso27001standard.com/2013/03/11/can-iso-27001-risk-assessment-be-used-for-iso-22301/#comments</comments>
		<pubDate>Mon, 11 Mar 2013 17:21:21 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[Annex A]]></category>
		<category><![CDATA[ISO 22301]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[risk treatment]]></category>
		<category><![CDATA[Risk Treatment Plan]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=2228</guid>
		<description><![CDATA[A few days ago I received the following question from one of our clients: &#8220;What is the difference between ISMS Risk Assessment and BCM Risk Assessment?&#8221; And, although the answer to this question might seem easy, in actuality it is not. Here&#8217;s the rest of his question: &#8220;&#8230; Because on your blog I found that [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2013/03/11/can-iso-27001-risk-assessment-be-used-for-iso-22301/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Cybersecurity Executive Order confirms how crucial information security is for critical infrastructure</title>
		<link>http://blog.iso27001standard.com/2013/02/25/cybersecurity-executive-order-confirms-how-crucial-information-security-is-for-critical-infrastructure/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cybersecurity-executive-order-confirms-how-crucial-information-security-is-for-critical-infrastructure</link>
		<comments>http://blog.iso27001standard.com/2013/02/25/cybersecurity-executive-order-confirms-how-crucial-information-security-is-for-critical-infrastructure/#comments</comments>
		<pubDate>Mon, 25 Feb 2013 18:15:12 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Information security]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=2221</guid>
		<description><![CDATA[For a long time a debate has been going on regarding whether information security/cybersecurity has something to do with critical infrastructure, and if yes, how important cybersecurity is for critical infrastructure. This dilemma is definitely resolved with President Obama&#8217;s Executive Order on Improving Critical Infrastructure Cybersecurity. For quite some time now, cyber attacks on various [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2013/02/25/cybersecurity-executive-order-confirms-how-crucial-information-security-is-for-critical-infrastructure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Main changes in the new ISO 27002 (2013 draft version)</title>
		<link>http://blog.iso27001standard.com/2013/02/11/main-changes-in-the-new-iso-27002-2013-draft-version/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=main-changes-in-the-new-iso-27002-2013-draft-version</link>
		<comments>http://blog.iso27001standard.com/2013/02/11/main-changes-in-the-new-iso-27002-2013-draft-version/#comments</comments>
		<pubDate>Mon, 11 Feb 2013 21:42:55 +0000</pubDate>
		<dc:creator>Dejan Kosutic</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[Annex A]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO 27002]]></category>

		<guid isPermaLink="false">http://blog.iso27001standard.com/?p=2215</guid>
		<description><![CDATA[In my previous blog post I analyzed the changes between the old ISO 27001 (published in 2005) and the 2013 draft; naturally, controls from ISO 27001 Annex A cannot change without changing ISO 27002 because the essence of these two standards is to be aligned. So, let&#8217;s take a look at what changes are proposed [...]]]></description>
		<wfw:commentRss>http://blog.iso27001standard.com/2013/02/11/main-changes-in-the-new-iso-27002-2013-draft-version/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
	</channel>
</rss>
