Documenting policies
Assign topic to the user
Answer: ISO 27001 is not prescriptive about how to document your information, so you can put all policies into a single document. To have all policies in a single document can make easier to manage them, but you have to take care not to finish with a document so big that it will become difficult or annoying for user to handle them.
These articles will provide you further explanation about how manage policies:
- One Information Security Policy, or several policies? https://advisera.com/27001academy/blog/2013/06/18/one-information-security-policy-or-several-policies/
- Is the ISO 27001 Manual really necessary? https://advisera.com/27001academy/blog/2014/02/03/is-the-iso-27001-manual-really-necessary/
Comment as guest or Sign in
Jan 11, 2018