Implemented controls
Assign topic to the user
Answer:
Our experience show us that companies typically have ca 80 controls implemented before the start of an ISO 27001 project, and then they have ca 20 to 30 controls to implement during the project.
The quantity of implemented controls does not have a direct impact in the certification, because information security management is about balancing needs and expectations with the level of acceptable risks (similar organizations may have different number of implemented controls and both can be certified).
This article will provide you further explanation about selecting controls:
- The basic logic of ISO 27001: How does information security work? https://advisera.co m/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/
This material will also help you regarding selecting controls:
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
Comment as guest or Sign in
Dec 04, 2018