Guest
Filling a SoA document
I am completing the SoA and wonder if I do need to complete for each objective and control, the ‘responsibility coloum’ or can this be left blank?
Assign topic to the user
Expert
Rhand Leal
Aug 06, 2017
Answer: ISO 27001 does not requires responsibilities to be included in the SoA, so you do not need to include this information because of the standard. Some organizations decide to include this information in the SoA so it becomes easier for them to identify who is responsible for each control (all information could be found in a single document). Of course, if you decide for this approach, if a control is considered not applicable, them you should left the field blank.
Comment as guest or Sign in
Aug 05, 2017
Aug 05, 2017
Aug 05, 2017