Expert Advice Community

Guest

Document lay-out

  Quote
Guest
Guest user Created:   Oct 21, 2018 Last commented:   Oct 21, 2018

Document lay-out

Lets explain my question through the [policy for change management] (Section A.12). In the policy is one related document in section 4: the change log (in electronic form). Does the formal structure of the change log has to be like defined in the [policy for information classification]? (classification level in the upper right corner… etc., etc.)
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Oct 21, 2018

In general, related documents (doesn’t matter in which way they exist (paper document, electronically, inside the information system etc.) from section 4 do they have to be compliant with the things we defined in the [policy for information classification]?

Answer:

The change log form, as well as any other document or record that is part of the ISMS, must be labelled accordingly the Information Classification Policy, as well as to follow the guidelines defined in the Procedure for Document and Record Control (sections 3.1 and 3.5), so the organization does not incur in a non conformity.

Of course, in the Information Classification Policy you may choose to exclude certain type of documents or records from being labelled, in order to make operations with those documents and records more easily. However, in such case you should assess if this would create some unacceptable risks.

These articles will provide you further explanation about document control and labeling:
- Information classification according to ISO 27001 https://advisera.com/27001academy/blog/2014/05/12/information-classification-according-to-iso-27001/
- Records management in ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/11/24/records-management-in-iso-27001-and-iso-22301/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Oct 21, 2018

Oct 21, 2018

Suggested Topics

Guest user Created:   Oct 25, 2018 ISO 27001 & 22301
Replies: 1
0 0

Recertification activities

Guest user Created:   Jun 10, 2024 ISO 27001 & 22301
Replies: 1
0 0

Non-mandatory documents