Accueil
Explorer
Soumettre la recherche
Mettre en ligne
S’identifier
S’inscrire
Publicité
BCS ISO 27001 LA Lecture Fahad Zaman.pdf
Signaler
FahadZaman38
Suivre
28 Mar 2023
•
0 j'aime
0 j'aime
×
Soyez le premier à aimer ceci
afficher plus
•
7 vues
vues
×
Nombre de vues
0
Sur Slideshare
0
À partir des intégrations
0
Nombre d'intégrations
0
Check these out next
IRJET- Educational Data Mining for Prediction of StudentsPerformance using Cl...
IRJET Journal
CC 207 Module.docx
PaulineTorion1
My thesis proposal
hungtruongquoc
Attendance management system project report.
Manoj Kumar
Develop project pia+ risk identification
Trilateral Research
Erudition- Institute Management System
IRJET Journal
online education system project report
Hagi Sahib
Hafsa 131003112307-phpapp02
prashanth Gudavalliprashanth
1
sur
19
Top clipped slide
BCS ISO 27001 LA Lecture Fahad Zaman.pdf
28 Mar 2023
•
0 j'aime
0 j'aime
×
Soyez le premier à aimer ceci
afficher plus
•
7 vues
vues
×
Nombre de vues
0
Sur Slideshare
0
À partir des intégrations
0
Nombre d'intégrations
0
Télécharger maintenant
Télécharger pour lire hors ligne
Signaler
Technologie
This is the lecture for the introduction of ISO 27001 Lead Auditor.
FahadZaman38
Suivre
Publicité
Publicité
Publicité
Recommandé
Academia ERP Presentation - College and University Management System
Arpit Badjatya
5.6K vues
•
39 diapositives
SURVEY ON ONLINE EXAMINATION SYSTEM USING ARTIFICIAL INTELLIGENCE
IRJET Journal
24 vues
•
3 diapositives
Alumni Record System
IRJET Journal
3 vues
•
5 diapositives
EST-Report[1] grp.pdf
RenuDeshmukh5
11 vues
•
31 diapositives
EST-Report[1] grp 15 (AutoRecovered).pdf
RenuDeshmukh5
25 vues
•
29 diapositives
Online Student Feedback System
EditorIJAERD
788 vues
•
3 diapositives
Contenu connexe
Similaire à BCS ISO 27001 LA Lecture Fahad Zaman.pdf
(20)
IRJET- Educational Data Mining for Prediction of StudentsPerformance using Cl...
IRJET Journal
•
35 vues
CC 207 Module.docx
PaulineTorion1
•
11 vues
My thesis proposal
hungtruongquoc
•
16.3K vues
Attendance management system project report.
Manoj Kumar
•
168.2K vues
Develop project pia+ risk identification
Trilateral Research
•
198 vues
Erudition- Institute Management System
IRJET Journal
•
4 vues
online education system project report
Hagi Sahib
•
58.4K vues
Hafsa 131003112307-phpapp02
prashanth Gudavalliprashanth
•
402 vues
System maintenance.ppt
MejanurRahmanJunayed
•
4 vues
Online Job Portal
Prateek Kulshrestha
•
7.9K vues
An Intelligent Career Guidance System using Machine Learning
IRJET Journal
•
7 vues
Chapter_1_INTRODUCTION.pdf
Kamal Acharya
•
6 vues
Chapter_1_INTRODUCTION.pdf
Kamal Acharya
•
8 vues
Chapter_1_INTRODUCTION.pdf
Technology Computer
•
7 vues
Project-Student Financial Service System
chezhiang
•
4.9K vues
NUS-ISS Digital Architecture Information Session
engtsze
•
261 vues
PurposeThis course project is intended to assess your abilit
TakishaPeck109
•
4 vues
THE CRYPTO CLUSTERING FOR ENHANCEMENT OF DATA PRIVACY
IRJET Journal
•
4 vues
Resume-Ishita_Kundu_2015
Ishita Kundu
•
236 vues
IRJET - Web Application for Sports Module
IRJET Journal
•
4 vues
Dernier
(20)
Computerized AIS (AIS, TPS and Double-Entry).ppt
franciskishushu
•
0 vue
MCQ.pptx
Sudipta Roy
•
0 vue
National Pharmaceutical Pricing Authority-WPS Office.pptx
Sudipta Roy
•
0 vue
Intelligent Document Processing IDP.pdf
JamieDornan2
•
0 vue
Biological Neural Network.pptx
Abdul Rehman
•
0 vue
7 Alpha Company Profile v1.0.pdf
AusafUrRahman3
•
2 vues
Google AI Hub Demystified.pdf
Supernova Media
•
0 vue
Monark Company Culture.pdf
CalebBenedict4
•
0 vue
Innovation to startup.pptx
ravikumark42
•
0 vue
Decision Transformers Model.pdf
JamieDornan2
•
0 vue
d9f0992b5cb6478fa0dfff092cccc2d2.pdf
ThnhNguynVn97
•
0 vue
different-os.pptx
leilibarekatin
•
0 vue
Medical Termination of Pregnancy Act.pptx
Sudipta Roy
•
0 vue
Antenna_Design__Measurements_Laboratory_Lectures.pdf
Fredrick Isingo
•
0 vue
Reinventing Kafka in the Data Streaming Era - Jun Rao
confluent
•
0 vue
DIMT '23 Session_Demo_ Latest Innovations Breakout.pdf
confluent
•
3 vues
different topics blogging articles
AishaSajidAishaSajid
•
0 vue
TRANSACTION CONCEPTppt.pptx
DummyTest9
•
0 vue
ServeDocs - User Guide.pdf
VivekPatil607881
•
0 vue
REFLEXES-PLP.pptx
Judi131
•
0 vue
Publicité
BCS ISO 27001 LA Lecture Fahad Zaman.pdf
© © A Road Towards
ISO 27001 Lead Auditor Certification • Presented by- Fahad Zaman Chowdhury Joint Secretary (Admin) Bangladesh Computer Society & Joint Director (ICT) Bangladesh Bank 1
© My Profile Professional: Joint
Director (ICT), Bangladesh Bank Member, Bangladesh Bank CIRT Cyber Security Practitioner Panelist, AFI Cyber Security Program, Malaysia Academic: MSc (CS, University of Malaya, Malaysia), MBA (Finance, DU), BSc (EEE, KUET) Certification: ISO 27001 LA, CDFOM, ECSA Academic/research Interests Information Security, Network Security, Game Theory, Security of Pervasive and Ubiquitous Computing Awards/fellowships/grants 1. Secured best paper award in 8th IEEE Control and System Graduate Research Colloquium (ICSGRC) 2017, Conference held in Shah Allam, Malaysia 2. Won IEEE quiz award in IEEE student congress organized by IEEE Malaysia Section & Asia Pacific University, Malaysia 2
© My Profile (Contd.) Publications
And Presentations 1.EDoS Eye: A Game Theoretic Approach to Mitigate Economic Denial of Sustainability Attack in Cloud Computing by Fahad Zaman Chowdhury, Mohd Yamani Idna Bin Idris , Miss Laiha Mat Kiah and M A Manazir Ahsan. In proceeding of 8th IEEE Control & System Graduate Research Colloquium (ICSGRC) 2017, Malaysia. 2. Economic Denial of Sustainability Mitigation Approches in Cloud- Analysis and Open Challenges by Fahad Zaman Chowdhury, Mohd Yamani Idna Bin Idris , Miss Laiha Mat Kiah and M A Manazir Ahsan. In proceeding of International Conference on Electrical Engineering and Computer Science (ICECOS) 2017, Indonesia. 3.An efficient fuzzy keyword matching technique for searching through encrypted cloud data by M A Manazir Ahsan, Fahad Zaman Chowdhury, Musarat Sabilah, Ainuddin Wahid Bin Abdul Wahab, Mohd Yamani Idna Bin Idris. In proceeding of 2017 International Conference on Research and Innovation in Information Systems (ICRIIS), Malaysia. 4. Seminar on "A Dynamic Game Modeling of EDoS Eye" presented in Post Graduate Research Excellence Symposium (PGRES) 2017 organized by faculty of computer science and information technology, University of Malaya, Malaysia. Memberships/affiliations 1. Joint Secretary (Admin), Bangladesh Computer Society 2. Member, Institute of Engineers Bangladesh (IEB) 3. Life Member, Bangladesh Computer Society 4. Member, Engineers Club, Dhaka 5. Former Ex-Co Member, IEEE UM Student branch Online Profile 1 https://scholar.google.com/citations?user=CaTbyOFiZQUC&hl=en (Google Scholar) 2. https://bd.linkedin.com/in/fahad-zaman-chowdhury-644a5427 (Linkedin) 3. https://www.researchgate.net/profile/Fahad_Chowdhury2 (ResearchGate) 3
© © Road Towards ISO 27001 Lead
Auditor Certification 4
© Topic 5 Conducting Audit Audit Findings Audit
Reporting Audit Follow-Up
© Conducting Audit 6 Auditing is
a Fact-Finding Process Not A Fault-Finding Process
© Conducting Audit 7 ü Objective
of an Audit ü Benefits of Audit ü Types of Audit ü Stages of the Audit (Stage 1 & Stage 2 ) ü Surveillance Audits ü Re-Certification Audits ü Principles of Auditing (Integrity, Fair presentation, Due Professional Care, Confidentiality, Independence, Evidence based approach) ü Responsibilities of a Lead Auditor ü Traits/Attributes of an Auditor ü Knowledge and Skills of Auditor
© Conducting Audit 8 Colleacting and
Verifying Information: Sources of information Collecting by means of appropriate sampling Audit Evidence Evaluating against audit criteria Audit findings Reviewing Audit Conclusions
© Conducting Audit 9 Auditor’s Task
: Verify Interviews Questions Observation Examination
© Conducting Audit 10 • What
do Auditors Examine? Documentation Records Hardware Software Processes People
© Audit Findings 11 Audit Findings
: ü Indicate conformity and non-conformity ü Lead to identification of opportunities for improvement or recording good practices ü Can be tremed compliance or non-compliance if the criteria selected based on legal or regulatory requirements
© Audit Findings 12 Fulfilment of
a requirement Factual evidence of a condition in accordance with a specified requirement Non fulfilment of a requirement Factual evidence of a condition not in accordance with a specified requirement
© Audit Findings 13 Major Non-conformity: ü
A significance non-conformance with specified requirements or ISMS requirements ü Failure of System ü Significance number of minor failures
© Audit Reporting 14 ü Record
the findings during the audit time and compile it to make it presentable or reportable ü Review with the auditee/ audit representative when in doubt ü Classify or grade the non-conformity ü Reach to a conclusion of the audit ü Conduct a closing meeting
© Audit Follow-Up 15 Audit follow-up
is required ü To verify and assess the effectiveness of the corrective/preventive actions by the organization. ü Involves: Verifying, Closing and/or Escalating Follow-up audit can vary based on the severety of the problem: ü A limited re-audit ü A renew of the new/amended documentation ü Include in the next audit
© Audit Follow-Up 16 Role of
auditee ü Understand the non-conformity raised ü Investigate the cause ü Identify action ü Select most appropriate actions and develop action plan ü Take corrective actions ü Internal verification of completion ü Inform auditor about implementation and plan for follow-up
© Audit Follow-Up 17 Role of
auditor ü Review corrective action plan ü Verifiy corrective actions ü Close out and confirm compliance report
© Question and Answer 18
© © Thank You All 19
Publicité