SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Clarification on Scope of Work

  Quote
Guest
Guest user Created:   Apr 24, 2020 Last commented:   Apr 24, 2020

Clarification on Scope of Work

1. What should be important considerations while defining Out of Scope in Statement of applicability?

2. If I have some systems which are currently running on obsolete technology or not in support technology, what does that mean for my ISO 27001 Stage 2 assessment and what impact it can have on certification?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 24, 2020

1. What should be important considerations while defining Out of Scope in Statement of applicability?

I'm assuming that by "Out of Scope" you are meaning controls that are not applicable.

Considering that, for a control to be considered not applicable in the Statement of applicability you have to be sure that:

  • there are no relevant risks you decided to treat that need this particular control to become acceptable risks
  • there are no legal requirements (e.g., laws, regulations, or contracts) that require this particular to be implemented

For further information, see:

2. If I have some systems which are currently running on obsolete technology or not in support technology, what does that mean for my ISO 27001 Stage 2 assessment and what impact it can have on certification?

If the information security risks related to these systems running in this situation are identified and evaluated as acceptable by your organization, then this situation won't have an impact in your certification process, because you performed the risk assessment and risk treatment required by the standard (ISO 27001 does  not require you to treat all risks, only those considered unacceptable)

On the other hand, if you consider the risks related to this technology as not acceptable, you will have to implement applicable controls (safeguards) before going to the Stage 2 certification audit.

These articles will provide you a further explanation about the certification audit:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 24, 2020

Apr 24, 2020

Suggested Topics