Expert Advice Community

Guest

Controls application

  Quote
Guest
Guest user Created:   Dec 12, 2017 Last commented:   Dec 12, 2017

Controls application

We produce a cloud-based web application that is hosted on XXXX and uses other outsourced infrastructure providers (like XXXX). The only physical equipment that the company owns and that is onsite in our offices is employee laptops. Considering this situation, are the ISO 27001 controls in Annex A sections A.11 (Physical and environmental security) applicable to us, since we don't have any servers or other major equipment onsite?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 12, 2017

Answer: According to ISO 27001 requirements, the applicability of controls from Annex A section A.11 on your office will depend on whether your employee's laptops have access to any information you want to protect (either if the information is stored or processed onsite or in the cloud), and the results of risk assessment identify risks to your premises that should be treated (e.g., there is an unacceptable risk that someone invades your office and steals the notebooks).

These articles will provide you further explanation about physical and environmental security:
- Physical security in ISO 27001: How to protect th e secure areas https://advisera.com/27001academy/blog/2015/03/23/physical-security-in-iso-27001-how-to-protect-the-secure-areas/
- How to implement equipment physical protection according to ISO 27001 A.11.2 – Part 1 https://advisera.com/27001academy/blog/2016/04/18/how-to-implement-equipment-physical-protection-according-to-iso-27001-a-11-2-part-1/
- How to implement equipment physical protection according to ISO 27001 A.11.2 – Part 2 https://advisera.com/27001academy/blog/2016/04/26/how-to-implement-equipment-physical-protection-according-to-iso-27001-a-11-2-part-2/

This material will also help you regarding Physical and environmental security:
- ISO 27001 Annex A Controls in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 12, 2017

Dec 12, 2017

Suggested Topics

Guest user Created:   Nov 27, 2018 ISO 27001 & 22301
Replies: 1
0 0

Controls application

Guest user Created:   Feb 14, 2020 ISO 27001 & 22301
Replies: 5
0 0

ISO 27018 versions