There was a general discussion of the link between ISO 27001 and the more general needs of digital repository audit and certification. It was agreed that the "shoe factory" example originating with Barbara Sierman was useful for focussing our thoughts ("what is the difference between a long term preservation environment and an information security management system of let's say a shoe factory.").
Discussion
ACTION: on all study chapter 4 of ISO 27001 in detail and post comments on the wiki, organised by subsection of the chapter, with reference to how it relates to TRAC/Nestor.
-- SimonLambert - 03 Apr 2007