Responsibilities in the Information security policy
Recently we have bought premium toolkit. We started to create an Information Security Policy document and we have following questions:
Relationship between CE mark and ISO 27001?
To make the documents helpful and ISO 27001 with other standards
Control A.5.1.1 Policies for information security - when to select it?
During the ISO27001:2013 implementation process it is of course mandataory at the first stage to define the ISMS scope, to obtain the support of the top management and to formalize a high level Information Security Policy. But during the SOA step is it necessary to select the ISO 27002 control related to Information Security Policy in order to write down a detailed Infomation Security Policy ?