Conformio ISO Documentation
Assign topic to the user
ISO 27001 does not prescribe how documents should be grouped, so organizations can develop documents as best fit their needs.
Besides the IT security policy, Conformio provides the following templates that you can use to split these items:
- Password Policy
- Clear Desk and Clear Screen Policy
- Backup Policy
In case you use the additional items, the same elements in the IT Security Policy will be automatically excluded.
For “Authorizations for information system use”, they are regulated through the Access Control Policy, whereas the authorizations themselves can be done simply through email, no specific type of record is needed.
For further information, see:
- One Information Security Policy, or several policies? https://advisera.com/27001academy/blog/2013/06/18/one-information-security-policy-or-several-policies/
Comment as guest or Sign in
Sep 17, 2021