SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Cryptographic Policy

  Quote
Created:   Jun 02, 2020 Last commented:   Jun 02, 2020

Cryptographic Policy

I am using your toolkit for implementation ISO 27001.
I am a bit confused because in your list of the required documents for ISO27001 is no requirement for a cryptographic Policy (nr. 65/66).

But in the list of our Auditor for ISO 27001 is this Policy a mandatory document.

So could u help me to understand this inconsistence?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jun 02, 2020

Please note that not all ISO 27001 Annex A controls require policies or procedures to be documented as part of their implementation, and cryptographic controls are one of those controls that do not need to be documented.  Considering that, first you should verify if there are any legal requirements (e.g., law, regulation, or contract) your organization must comply to, requiring this policy to be documented. In case there are no such legal requirements, then you should politely ask the auditor for clarification about why he considers documenting this policy to be mandatory, explaining that you did not find reasons to document the policy (i.e., legal requirements demanding its documentation).

These articles will provide you a further explanation about documentation and auditors:

This material will also help you regarding auditing:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 01, 2020

Jun 01, 2020

Suggested Topics

Guest user Created:   Nov 17, 2022 ISO 27001 & 22301
Replies: 1
0 0

Controls 10.1.1 + 10.1.2

Guest user Created:   Mar 31, 2018 ISO 27001 & 22301
Replies: 1
0 0

Use of cryptographic controls