SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Applicability of ISO 27001 procedures in scope with multiple departments

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Applicability of ISO 27001 procedures in scope with multiple departments

1. If there are, say, 2 business units A & B in the isms scope. On risk assessment it was found that A requires a specific control to mitigate a specific risk (e.g. backup of its systems to maintain business operations in the event of a disaster). So a standard or policy has been written up that states that requirement. But, the standard or policy states the scope is the scope defined in the scope document. And scope document says both A & B are included. So the question is, does that control requirement apply to only A or all units?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
DejanK Jan 12, 2016

This questions stems from the fact that many of our existing documentation such as standards and procedures have been written up that gives the reader the impression that the controls mentioned in these documents are minimum requirements that are to be applied to all in-scope-units; whereas, in the first instance the control would have been chosen as an answer to one unit's risk.

Answer:

You should decide on your own whether your documents (e.g. policies, procedures, etc.) will apply to your whole organ ization, to your whole ISMS scope, or only to a particular organizational unit. However, when writing your documents, then you have to specify clearly to which organizational units they apply to; you can also specify this information in the Statement of Applicability.

This article can also help you: How to define the ISMS scope https://advisera.com/27001academy/blog/2014/10/13/how-to-define-the-isms-scope/

2. Can or should the scope document be reviewed periodically?

Answer:

ISMS scope document should be definitely reviewed periodically, typically this is once a year, before you start doing the risk assessment.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016