Expert Advice Community

Guest

Annex A Applicability

  Quote
Guest
Guest user Created:   May 11, 2020 Last commented:   May 11, 2020

Annex A Applicability

I would ask him about completing the Statement of Applicability as our starting point to understand the scale of work (being such a small business) with regards to Annex A and which of the 114 controls are going to be necessary.

0 0

Assign topic to the user

ISO 27001 STATEMENT OF APPLICABILITY

List all controls and determine which are applicable and why.

ISO 27001 STATEMENT OF APPLICABILITY

List all controls and determine which are applicable and why.

Expert
Rhand Leal May 11, 2020

Working on the Statement of Applicability as your starting point is not a good approach, because it only documents the results of previous efforts.

According to the ISO 27001, to understand which of the 114 controls are going to be necessary you need to perform the identification of applicable legal requirements and a risk assessment and treatment process.

The identification of legal requirements will help you identify laws, regulations, and contracts that demand the implementation of controls and the risk assessment and treatment will help you identify which controls you need to implement to handle the most relevant risks.

These articles will provide you a further explanation about ISO 27001 and application of controls:

These materials will also help you regarding ISO 27001 and application of controls:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 11, 2020

May 11, 2020