ISO27002 Clause 12.1.1
Assign topic to the user
Or does the topic mean something else of documents for IT positions?
Answer: The control A.12.1.1 (Documented operating procedures) is related to documentation of operational activities like computer start-up and close-down, backup, equipment maintenance, media handling, etc.
To identify which documents are related to an IT System's Engineer role you should document, you need to verify in the IT System's Engineer job description which activities he performs are related to information processing and communication facilities and, considering the results of risk assessment, legal requirements, decisions of top management and operational needs, which procedures should be documented.
Some examples of documents related to this controls are "Backup policy", "IT operational procedures", "Network management", and "Systems monitoring".
These articles will provide you further explanat ion about writing policies and procedures:
- 8 criteria to decide which ISO 27001 policies and procedures to write https://advisera.com/27001academy/blog/2014/07/28/8-criteria-to-decide-which-iso-27001-policies-and-procedures-to-write/
- How to structure the documents for ISO 27001 Annex A controls https://advisera.com/27001academy/blog/2014/11/03/how-to-structure-the-documents-for-iso-27001-annex-a-controls/
These materials will also help you regarding writing policies and procedures:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Aug 12, 2017