Expert Advice Community

Guest

Statement of Acceptance of ISMS Documents

  Quote
Guest
Guest user Created:   Oct 14, 2021 Last commented:   Oct 14, 2021

Statement of Acceptance of ISMS Documents

We're a fairly small organization with only a few employees and a handful of 3rd parties helping us out with sales, compliance etc. We have used the "Statement of Acceptance of ISMS Documents". Could that be sufficient for "awareness training"? I mean that they sign this after reading all the documentation? Or we could add a few questions related to the policies that they were required to answer when submitting the statement? Would this be sufficient? Or is it expected by the auditors that we've bought some online tool to manage this such as the awareness training you and other companies offer?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Oct 14, 2021

Only the "Statement of Acceptance of ISMS Documents" is not enough to be compliant with ISO 27001 requirements related to competence (clause 7.2) and awareness (clause 7.3).

You will also need information regarding actions taken to provide the necessary competence/awareness (e.g., reading of the documentation, awareness presentation, etc.), and evaluation of actions effectiveness (e.g., questions about the presented documentation).

For those, you can use the Training and Awareness Plan template included in your toolkit, in folder 9 Training and Awareness. Both “Training and Awareness Plan” and "Statement of Acceptance of ISMS Documents" will be sufficient to evidence awareness about the documentation.

This article will provide you a further explanation about awareness and training:

This material will also help you regarding awareness and training:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Oct 14, 2021

Oct 14, 2021

Suggested Topics