Expert Advice Community

Guest

Justifications in the SoA

  Quote
Guest
Guest user Created:   Nov 12, 2019 Last commented:   Nov 12, 2019

Justifications in the SoA

SoA > Can "Mandatory according to iSO27001 or GDPR" be a valid justification or does it have to be a specific risk?

0 0

Assign topic to the user

ISO 27001 STATEMENT OF APPLICABILITY

List all controls and determine which are applicable and why.

ISO 27001 STATEMENT OF APPLICABILITY

List all controls and determine which are applicable and why.

Expert
Rhand Leal Nov 12, 2019

 A control from ISO 27001 Annex A can be applicable based on these general justifications:

  • There are unacceptable risks which treatment requires the control implementation
  • There are legal requirements which demands the control implementation
  • There is a top management decision requiring the control implementation

Considering that, it is acceptable by ISO 27001 to justify the applicability of a control as required by GDPR, but not to use the ISO 27001 as justification, because it does not require any control to be implemented (for the standard, the implementation is defined by the above-mentioned conditions).

This article will provide you further explanation about controls selection:
- The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 12, 2019

Nov 12, 2019

Suggested Topics

Gerry Created:   Sep 18, 2023 ISO 27001 & 22301
Replies: 2
0 0

Risk Treatment Advice

Guest user Created:   Dec 23, 2021 ISO 27001 & 22301
Replies: 1
0 0

Risk assessment Vs SoA