Expert Advice Community

Guest

Control A7.1.1

  Quote
Guest
Guest user Created:   Apr 20, 2020 Last commented:   Apr 20, 2020

Control A7.1.1

Control A7.1.1 is partially applied to Brazil under the law. In this case, can I put NO in the SOA and explain this or do I have to put YES and explain the exceptions?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 20, 2020

By your question, it is not clear if the law you are referring to demands screening, or defines restrictions to screening.

Considering that, in case you identify a need to implement control A.7.1.1, but this implementation has legal limitations, you have to state in the SoA that this control is applicable with limitations, briefly explaining the exceptions. An example of a justification where you have a legal requirement demanding the control (e.g., a customer contract), but you also have another legal requirement defining limitations on its applicability would be "Control required by Customer contract ABC, limited by Brazilian Consolidation of Labor Laws (CLT)".

This article will provide you further explanation about applying security controls:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 20, 2020

Apr 20, 2020

Suggested Topics