Difference in clauses
When I read ISO 27001 I had one question, I wanted to inquire about it, what is the difference between clause (6.1.2) and clause (8.2), as well as clause (6.1.3) and clause (8.3), is it just a repetition of the information? Please explain. Thank u very much
Assign topic to the user
Clauses 6.1.2 and 6.1.3 refers to the planning, and first application, of risk assessment and risk treatment ("The organization shall define and apply..."), while clauses 8.2 and 8.3 refers to subsequent application of the process ("(...) at planned intervals or when significant changes are proposed or occur, (...)").
Comment as guest or Sign in
Apr 17, 2020