Physical security Policy
Assign topic to the user
Hi Vijay
- CCTV is not a requirement in ISO 27001. You should implement this cotnrol when the risk assessment pushes you to it.
- The two issues you present is not an incident, but a non conformity. An incident is 'en event that prevents you from reaching your objectives'.
- I do not really understand what you mean by 'compensating controls' in this case. if you provide more details I'll be able to answer.
Regards
Jaan-Luc
Comment as guest or Sign in
Jan 12, 2016

