Template contents
I had noted that the toolkit covered the elements below but what about 18.1.2a&b, 18.1.3, 18.1.4&a&b, 18.2.1 and 18.2.2?
Assign topic to the user
Control A.18.1.2 is covered by the IT security policy template.
Regarding the other mentioned controls, we do not have those included in our toolkit. Please note that Advisera's ISO 27001 Documentation Toolkit does not have a document for each and every control from ISO 27001 because of the following reasons:
1) ISO 27001 does not require each and every control to be documented
2) If the toolkit had a document for each control, there would be too many documents, and this would be an overkill for smaller and mid-size companies.
Since our target are SMEs, we have decided to include an optimum amount of documents for companies of this size - the toolkit includes:
All the mandatory documents - e.g. Information Security Policy, Statement of Applicability, Risk Assessment Methodology, Access Control Policy, etc.
Documents that are not mandatory, but are commonly used - e.g. BYOD Policy, Classification Policy, Password Policy, Backup Policy, etc.
You can see a full list of documents included in the toolkit in this page: https://advisera.com/27001academy/iso-27001-documentation-toolkit/
Comment as guest or Sign in
Nov 15, 2019