Expert Advice Community

Guest

Acceptable use policy and telework

  Quote
Guest
Guest user Created:   Feb 21, 2017 Last commented:   Feb 21, 2017

Acceptable use policy and telework

1 - Can I refer to for example the ‘Acceptable Use Policy’ as an existing control to prevent the theft of a smartphone (with company information on it) of an employee? Or do I have to mention this in the Risk Treatment Plan?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 21, 2017

Answer: Yes, because the ‘Acceptable Use Policy’ provided with your ISO 27001 & ISO 22301 Premium Documentation Toolkit defines clear rules for the use of the information system and other information assets, including rules regarding the prevention of unauthorized access to mobile devices both within and outside of the organization’s premises.

Regarding mentioning it in the Risk Treatment Plan, you should do this only if the control is still to be implemented or if you decided to make changes in the current implemented policy.

In the video tutorials that came with your toolkit, you can see examples of how to fill out all the data for Risk treatment.

2 - What does the Standard say about an employee who works from home?

Answer: Regarding employees who work from outside the premises, the standard has the control A.6. 2.2 - Teleworking, which basically means the organization has to ensure that proper security measures are implemented in the site and on communication services to ensure proper access, processing and storage of information.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 21, 2017

Feb 21, 2017

Suggested Topics