Expert Advice Community

Guest

Document control template

  Quote
Guest
Guest user Created:   Jul 15, 2018 Last commented:   Jul 15, 2018

Document control template

A question pertaining to document control
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 15, 2018

Does the Retention time mean that all entries related to the ISMS that are in the mail register (in our case our CRM) have to be deleted after X (three) years or ALL registrations which are older than three years. Moreover why should you want to delete entries of documents that may still be relevant? I find this document retention situation where mail is concerned very very confusing.

Answer: The retention time refers to entries related to the ISMS only, and it must be defined considering precisely the time frame you consider that information will be relevant to the organization. For example, if you consider that the information in your incoming mail register only will be irrelevant after 5 years, then you must define the retention time as 5 years. Issues you should consider for defining the retention time are business objectives, contractual or legal clauses.

This article will provide you further explanation about document control:
- Records management in ISO 27001 and ISO 22301 https://advise ra.com/27001academy/blog/2014/11/24/records-management-in-iso-27001-and-iso-22301/

These materials will also help you regarding document control:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 15, 2018

Jul 15, 2018