Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • ISO27001 clause & controls alignment

    Please note that there is no connection between individual clauses to particular controls.

    This is so because the purpose of the main part of the standard (clauses 4 to 10) is to manage security (e.g., risk management, internal audit, etc.), whereas the purpose of Annex A is to decrease risks with controls.

    The main part of the standard determines how to select safeguards, how to manage them, how to measure if they are successful, and so on, whereas Annex A controls describe what needs to be implemented.

    For further information, see:

Page 57 of 1130 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +