Writing procedures
Assign topic to the user
Answer: The ultimate responsibility is of the ISO implementer, but in fact this is a four-hands work. The ISO implementer provides knowledge related to standard's requirements that must be fulfilled and the IT staff provides information about current technologies and IT processes. It is important to note that other areas, like HR and facilities, may also be involved in the development of other ISMS documents.
These articles will provide you further explanation about developing documents:
- Seven steps for implementing policies and procedures https://advisera.com/27001academy/knowledgebase/seven-steps-for-implementing-policies-and-procedures//
- 8 criteria to decide which ISO 27001 policies and procedures to write https://advisera.com/27001academy/blog/2014/07/28/8-criteria-to-decide-which-iso-27001-policies-and-procedures-to-write/
- How to write an easy-to-use BYOD policy compliant with ISO 27001 https://advisera.com/27001academy/blog/2015/09/07/how-to-write-an-easy-to-use-byod-policy-compliant-with-iso-27001/
Comment as guest or Sign in
Aug 30, 2018