Expert Advice Community

Guest

Evidences for policies and controls

  Quote
Guest
Guest user Created:   Jul 12, 2017 Last commented:   Jul 12, 2017

Evidences for policies and controls

What logs and what forms and what records do i need for each policy and its control?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 12, 2017

Answer: There is no generic answer for this question, because depending upon the policy or control objective, the requirements regarding which should be kept as compliance evidence will vary.

For example, for a backup policy, a record identifying the date, content and ID of the backup media is required, while for access control policy an user account creation record would be needed, and they basically do not share any kind of information field.

So, what I can say to you for identifying required logs, forms and records needed is to evaluate ISO 27001 requirements and which results you expect from an implemented policy or control and which information you need to present, or evaluate, to prove to someone you are actually achieving those results.

This article will provide you further explanation about mandatory records for ISO 27001:
- List of mandatory documents required by ISO 27001 (2013 revision) https://advisera.com/27001academy/knowledgebase/list-of-ma ndatory-documents-required-by-iso-27001-2013-revision/

These materials will also help you regarding mandatory records for ISO 27001:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 12, 2017

Jul 12, 2017

Suggested Topics

Guest user Created:   Mar 21, 2019 ISO 27001 & 22301
Replies: 1
0 0

Templates content

Guest user Created:   Apr 15, 2017 ISO 27001 & 22301
Replies: 1
0 0

Management decisions

Guest user Created:   Dec 08, 2016 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 implementation