SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Controls selection

  Quote
Guest
Guest user Created:   Jan 24, 2019 Last commented:   Jan 24, 2019

Controls selection

Firstly, I have spent the past few days reviewing samples of your 27001 templates and training materials … very impressive … Thank You … it’s a great resource. May I ask a question? As it will influence whether XXXXXX go for a 27001 certified ISMS. XXXXXX is mandated to implement and maintain an ISMS, I have been made responsible for delivery of the ISMS project and have executive support and resourcing (people and finances). I would prefer to use 27001 for the ISMS (so we can be certified), however XXXXXX do not wish to use any of the 27002 controls, instead XXXXXX have invested our efforts in CIS20 controls. I understand XXXXXX select whatever controls are relevant, however my concern is if I don’t refer to any of the 27002 controls listed in Annex A of 27001, then XXXXXX will not be able to certify to 27001.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jan 24, 2019

Another concern is CIS20 does not have (HR and physical security), whereas 27002 does. The proposed scope of XXXXXX ISMS will not include (HR and physical security), it would include only relevant CIS20 controls. (I understand I ca n add others, but due to scope do not want to add). So my question is … Can XXXXXX have a certified 27001 ISMS using CIS20 controls only?

Answer:

First it is important to note that all controls from ISO 27001 Annex (those controls are the same as the ones in ISO 27002) must be considered during an ISMS implementation complaint with ISO 27001. For all controls from Annex A you have to identify if they are applicable or not, and justify why they are applicable or not.

Second thing is, most of CIS 20 controls can be related to ISO 27001 Annex A controls (e.g., CIS control “Inventory and Control of Hardware Assets” can be related to ISO 27001 controls “A.8.1.1 Inventory of assets” and “A.8.1.2 Ownership of assets”), so in a sense when you implement CIS 20 controls you are considering particular controls from Annex A as applicable.

However you will need to list all the ISO 27001 controls that are not covered by CIS 20 and decide whether they are applicable or not.

This article will provide you further explanation about selecting controls:
- The basic logic of ISO 27001: https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

This material will also help you regarding ISO 27001:
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
- Overview of ISO 27001:2013 Annex A https://advisera.com/27001academy/iso-27001-controls/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 24, 2019

Jan 24, 2019

Suggested Topics

Guest user Created:   May 29, 2019 ISO 27001 & 22301
Replies: 1
0 0

Physical controls selection

Guest user Created:   Sep 20, 2017 ISO 27001 & 22301
Replies: 1
0 0

Controls selection

Guest user Created:   Oct 22, 2021 ISO 27001 & 22301
Replies: 1
0 0

AML-ISO 27001