SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

A12.1.1. Documented operating procedures

  Quote
Created:   Apr 14, 2020 Last commented:   Apr 20, 2020

A12.1.1. Documented operating procedures

Hi, I am struggling to understand the concept and information you would document to satisfy the A12.1.1. Documented operating procedures control. Everything that we have identified in the risk assessment and included in the SoA is going to be documented witin the releveant procedural docs that we create. I really don't understand what is the relevance of aforementioned control

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 17, 2020

The purpose of control A.12.1.1 is to make it clear that all structured activities for any control from section A.12 need to be documented.

To use example of control A.12.1.2 (Change management) - if you have any kind of established process for managing changes for your operational systems, then you must document them (e.g. in the form of a procedure) because of control A.12.1.1; if you have only some unstructured activities for A.12.1.2, then you do not need to document them.

Quote
0 0
Guest
Ric Grime Apr 20, 2020

So i this case is it ok to just say yes in the SOA, because i will havesome documented procedures, and for justification I will namethe procedures in the SoA? no need to wite a more specific doc regarding 12.1.1? 

As always thank you, you guys are the best and templates very helpful

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 14, 2020

Apr 20, 2020