Expert Advice Community

Guest

Access controlAlign IT services continuity with ISO 22301

  Quote
Guest
Guest post Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Access controlAlign IT services continuity with ISO 22301

We have received this question: "Access control - user vs technical? How do I distinguish the difference in ISO27002? This is regarding ISO27002 - section 9 Access control 9.2 vs 9.4" Answer : The rights are given to users (people) to access information (e.g. physical documents), applications, hardware and locations (buildings and rooms). The correct management of this aspect is covered by clause 9.2. Clause 9.4 covers ‘how’ the access rights should be implemented in the technology to make sure the data on the computer systems (including mobile devices and telephony) are accessed according to the rules fixed by clause 9.2.Is ISO 27031 a good option to align IT services continuity (aka DRP) with ISO 22301 (BCMS)?
0 0

Assign topic to the user

ISO 22301 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 22301 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
DejanK Jan 12, 2016

Juliano,

Yes - ISO 27031 is a standard that can help you develop the IT side of your business continuity - i.e. disaster recovery; ISO 27031 is fully compliant and complementary to ISO 22301.

However, if you are a smaller company ISO 27031 could be too much for you - it is more intended for larger companies.

Quote
0 0
Guest
Guest post Jan 12, 2016

The fact that ISO 27031 was launched before ISO 22301, may exist some gaps between the two standards?

Quote
0 0
Guest
DejanK Jan 12, 2016

There are no gaps because the predecessor of ISO 22301 was BS 25999-2 (these two are very similar), and BS 25999-2 did exist at the time ISO 27031 was launched.

Quote
0 0
Guest
Guest post Jan 12, 2016

And about ISO 24762?

Is there any difference with ISO 27031?

Quote
0 0
Guest
DejanK Jan 12, 2016

ISO 24762:2008 is withdrawn (see here: https://www.iso.org/standard/41532.html so ISO 27031 is the most relevant standard now for technology aspect of business continuity.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics