Control A.6.1.5 project management in ISO 27001:2013
Assign topic to the user
Answer: The standard only says that you need to address information security in any type of the project - this means you have to make sure that the information is protected in all your projects. Usually, this can be done the following way:
- include security objectives in overall project objectives
- Include security specifications in your project description
- perform a risk assessment specifically for the project you are to undertake
- make sure security rules/technology are included in all the steps/tasks of the project
- test if the project deliverables are compliant with security specifications
Comment as guest or Sign in
Jan 12, 2016