Assign topic to the user
In this case, you only need to include in the asset register the outsourcing organization as a service provider.
Risks related to the outsourcing organization (i.e., risks related to hardware/software used by them) you can handle through the supplier security policy.
These articles will provide you a further explanation of asset register and supplier security:
- How to handle Asset register (Asset inventory) according to ISO 27001 https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/
- 6-step process for handling supplier security according to ISO 27001 https://advisera.com/27001academy/blog/2014/06/30/6-step-process-for-handling-supplier-security-according-to-iso-27001/
Comment as guest or Sign in
Sep 20, 2021

