SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Are confidentiality level and change history mandatory in all documents?

  Quote
Guest
Guest user Created:   Apr 08, 2016 Last commented:   Apr 08, 2016

Are confidentiality level and change history mandatory in all documents?

Is Confidentiality level and Change history table in the Document and record control procedure applied only to ISMS documents or to all documents and procedures in organization?
0 0

Assign topic to the user

ISO 27001 INFORMATION CLASSIFICATION POLICY

Define the classification levels and how to protect the information.

ISO 27001 INFORMATION CLASSIFICATION POLICY

Define the classification levels and how to protect the information.

Expert
Dejan Kosutic Apr 08, 2016

Answer:

The answer for those 2 elements is different:
1) If you have published the Classification policy, then you have to comply with your own policy - if in that policy you have defined that confidentiality level needs to be written in all of your documents, then you have to do so. If you didn't develop such policy, then there is no requirement in the standard to write the confidentiality level in all documents.
2) Regarding change history, ISO 27001 requires you to have this (or something similar) in your ISMS documentation. However, if you find this useful, then you can apply it to all the other documents as well.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 07, 2016

Apr 07, 2016