Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Including SOC 2 controls in SoA

    1. Are we required to include the SOC2 controls in the ISO 27001 Statement of Applicability?

    In case the SOC2 controls are applied to elements included in the ISMS scope, then you need to include them in the Statement of Applicability, but please note that some of ISO 27001 Annex A controls can be used to fulfill the Trusted Service Criteria used by SOC2, so in these cases, you can refer directly to the related Annex A controls.

    Also is important to note that, to include the SOC2 controls in the Statement of Applicability, you first need to review your risk assessment and risk treatment, and the applicable legal requirements, to ensure that you have the proper basis to include these controls in the SoA.

    This article will provide you a further explanation about ISO 27001 and SOC 2:

    2. If we were to add all of the SOC2 controls this year, would all these controls be tested during this year's external surveillance audit? I'm planning out the scope of the internal audit and which controls to test, but we have limited resources and time. It seems duplicative to me to include the SOC2 controls since those are tested independently as part of the SOC2 audit. I understand an internal audit is not required for the SOC2 certification, but I see the benefit of performing an internal review to identify issues that could be mitigated before the SOC2 cert audit.

    Please note that added controls need to be audited in the next surveillance audit because their impact on the information security levels needs to be verified.

    Considering your limited resources and time, an alternative could be to include first the controls that have the biggest impact on information security (i.e., they are the single or main controls applied to treat related risks) and leave other less impacting controls to be included in the next year. Additionally note that since some controls of Annex can be used for SOC2, this can reduce your need for resources and time.

  • ISO 27001 confidentiality

    Confidentiality is mentioned in the following sections and clauses:

    • 0 Introduction – 0.1 General
    • Clause 6.1.2 c) 1) – Information security risk assessment
    • Clause 7.5.3 b) – Control of documented information
    • Control section A.10.1 – Cryptographic controls
    • Control A.13.2.4 – Confidentiality or nondisclosure agreements

    This article will provide you a further explanation about ISO 27001:

    These materials will also help you regarding ISO 27001:

  • Documenting Statement of Applicability

    1. How to start documenting Statement of Applicability.

    To start documenting the Statement of Applicability you need to perform a risk assessment and risk treatment, to identify the relevant risks and controls (from ISO 27001 Annex A or other sources) you will implement to treat them. Additionally, you need to identify legal requirements (e.g., laws, regulations, and contracts) which require the implementation of specific controls.

    For further information, see:

    2. What approach to follow?

    According to ISO 27001, the following information must be included in the SOA:

    • All applied controls
    • Justification for inclusions
    • Implementation status
    • justification for exclusions of controls from Annex A

    You can also add information you consider relevant to help manage the ISMS (e.g., a brief description of how the control is implemented).

    Regarding the format, you can adapt the information to any format your organization considers proper (a document, a spreadsheet, etc.)

    To see how a Statement of Applicability of compliant with ISO 27001 looks like, please see the free demo on this link: https://advisera.com/27001academy/documentation/statement-of-applicability/

    3. Who all should one interact with?

    In the development of the Statement of Applicability you need to interact with those who participated in the risk assessment and treatment, and in the identification of legal requirements, and they should be the managers and key personnel of the related areas or processes (e.g., for IT, you need to interact with IT manager and systems’ administrator, for Finance, you need to interact with the Finance Manager and a finance specialist, etc.).

    This information may help you to start, but please note that this material depends on the contribution of our readers and some of them may be outdated. is strongly recommend hiring legal expert advice to support this activity:

    For further information, see:

  • Critical areas to prioritize focus during implementation

    This answer will depend on the results of risk assessment and the identification of legal requirements (e.g., laws, regulations, and contracts), because they will allow you to identify the areas which concentrates the most relevant risks, and which are subjected to the greatest impacts in case of legal requirements noncompliance.

    Besides the areas where ISO 27001 will be implemented, you also should add some emphasis on management support, project management, and training, to ensure availability of resources and employee engagement.

    For further information, see:
    - ISO 27001/ISO 27005 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/
    - The basics of risk assessment and treatment according to ISO 27001 [free webinar on demand] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/
    - How to identify ISMS requirements of interested parties in ISO 27001 https://advisera.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/
    - ISO 27001 project – How to make it work https://advisera.com/27001academy/blog/2013/04/22/iso-27001-project-how-to-make-it-work/

  • Recommended system/application to control documents, incidents and other stuff from ISO standards

    It's our policy not to make recommendations about specific tools owned by other organizations, since the selection of a tool will depend on specific requirements and needs of each organization, and we can’t ensure they are fully compliant with ISO management standards.

    However, we’d like to invite you to know our system for implementation and management of an ISMS compliant with ISO 27001, from which you can control documents, incidents, and other features required for compliance with ISO 27001:

  • The best KPIs for monitoring metrics

    ISO 27001 does not prescribe which performance indicators should be adopted by organizations, so there is no such thing as best KPIs, and organizations must define them according to their own needs and objectives. Some common issues organizations should take into account when defining KPIs are:

    • Business relevant: indicator aligned to clear business objectives or legal requirements
    • Process integrated: a KPI should add the least amount of work possible into business processes.
    • Assertive: the indicator should be capable of pinpointing relevant issues that need attention.

    As general examples we have:

    • Percent of business initiatives supported by the ISMS
    • Number of security-related service downtimes
    • Percent of controls assessment performed
    • Number of improvement initiatives

    These articles will provide you a further explanation about performance indicators and security objectives:

  • Business relevant data

    In the context of ISO 27001, ‘business-relevant data’ are those identified as:

    • paramount for the achievement of business objectives, results, and outcomes;
    • impacted by the most relevant risks identified in the risk assessment;
    • related to the fulfillment of legal requirements (e.g., laws, regulations, and contracts).

    In short, they are the information that will cause the most negative impact in case their confidentiality, integrity, and/or availability being compromised.

    In the Risk Assessment Table template included in your toolkit, you have a tab with examples of information security assets, and there is a specific category about data and information. This template is located in folder 5 Risk Assessment and Risk Treatment.

    These materials will also help you regarding ISO 27001 and information identification:

  • Implementation issues

    1. What implementation issues do you usually have?

    I’m assuming you are referring to ISO 27001 implementation.

    Considering that, the main challenges related to ISO 27001 implementation are:

    • Lack of management support: without this support, you won't have the minimal resources and engagement to implement the required controls.
    • Not using a project management approach: such implementation involves coordinating several people to perform dozens of activities, and without a methodology, you will finish inside a huge mess with no security at all.
    • Lack of time for the implementation project: The project can be very important, but normally, there are a lot of urgent things happening that postpone the project.
    • ISMS scope wrongly defined: not protecting information that really matters.
    • Documentation: Procedures excess or lack of details may compromise operations.

    This article will provide you additional information:

    2. Do you have implementation shortcuts that helps you streamline an implementation?

    Our ISO 27001 Documentation Toolkits are designed to be easy to use (minimal knowledge of the standard is required), listing folders and files in the order they must be implemented. Additionally, you can count on many resources on our site to help you implement the ISMS, like the free download content, blog articles, and at our Expert Advice Community, you can send your questions and scheduled meetings with our experts (sessions included in the toolkit).

    As examples of articles and similar material I can mention:

    To see how the toolkit documents look like, please access the free demos at this link: https://advisera.com/27001academy/iso-27001-documentation-toolkit/

    These materials will also help you regarding ISO 27001 implementation:

  • Best methodology for information security risk assessment

    1. What is the best methodology for an information security risk assessment?

    Please note that there is no single answer for this question because the “best” methodology will depend on many variables like business context, objectives, internal culture, etc. You can even write your own methodology if you want.

    Now, the most commonly used methodology for information security risk assessment is the asset-threat-vulnerability approach, mostly because it was part of the previous version of ISO 27001.

    For further information, see:

    To see how risk assessment and risk treatment documents (including the Statement of Applicability) compliant with ISO 27001 look like, please see the free demos of this toolkit: https://advisera.com/27001academy/iso-27001-22301-risk-assessment-toolkit/

    2. How to ensure if privacy principles are dealt with in accordance with relevant legislation and regulations? If the client says that he is performing an assessment to ensure he is in line with the DPA, is this information enough to make him compliant with clause 18.1.4?

    Please note that control A.18.1.4 (Privacy and protection of personally identifiable information) requires PII to be protected as required by relevant applicable legislation and regulation, and to evidence conformity, with the control the client needs to present not only which legislation and regulation he/she must comply with, but also which controls are implemented and evidence that the control is performing as expected. 

    For example, if legislation requires information availability, then the client has to say how compliance is ensured (e.g., by implementing a backup policy), and presents evidence that the control is implemented (e.g., by showing backup generation logs and backup test results). So, only by stating that assessment is performed is not enough to provide evidence of compliance with control A.18.1.4.

  • Asset Classification Best Practices

    Good practice suggests that information assets classification should be done through a four-step process:

    • information assets should be entered in an Inventory of Assets, so you know which assets to protect
    • information assets should be classified, considering their value to the organization and the impact if compromised
    • information assets should be labeled, so people can identify their classification
    • information assets should be handled in a secure way, considering their classification level

    For further information, see:

    These materials will also help you regarding risk assessment and information classification:

Page 198-vs-13485 of 1130 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +