Expert Advice Community

Guest

Change policy

  Quote
Guest
Guest user Created:   Dec 01, 2018 Last commented:   Dec 01, 2018

Change policy

I am ISMS-Manager at our Company and due to agile software development the request arises, that deployments to the Pre-Production environment can be done without raising a change in advance. This Pre-Production is under control of our RUN-Space, that operates as certified ISO 27001 realm.
0 0

Assign topic to the user

ISO 22301 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 22301 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 01, 2018

Do you think it is possible to exclude A.12.1.2 for this area from our applicable controls without loosing the certification status?

Answer:

If I understood correctly, the only issue in your current change process is about raising the change in advance. Considering that, the standard requires to control the changes, not necessarily to "raise" them in advance, so there is no need to exclude all the control (you can only exclude the "raise" in advance part).
To exclude a control you have to demonstrate that this exclusion won't arise unacceptable risks, neither will mean not fulfilling contracts, laws or other legal requirements that your organization must be compliant with.

If you can satisfy these conditions this exclusion will not affect the ISO 27 001 certification (but it does not seem your case).

This article will provide you further explanation about controls applicability:
- The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 01, 2018

Dec 01, 2018

Suggested Topics

Guest user Created:   May 08, 2020 ISO 27001 & 22301
Replies: 1
0 0

Change management policy

Guest post Created:   Jan 12, 2016 ISO 27001 & 22301
Replies: 1
0 0

Change the top-level policy

Igor Created:   Mar 17, 2025 ISO 27001 & 22301
Replies: 0
0 0

Secure Development policy