SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Documenting roles and responsibilities

  Quote
Guest
Guest user Created:   Jun 06, 2019 Last commented:   Jun 06, 2019

Documenting roles and responsibilities

We have implemented ISO 9001:2015 ans 27001:2013 standard in our organisation. I have one doubt.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jun 06, 2019

We have listed the roles, responsibilities and authorities in the job description maintained by the HR team for each functions. These roles, responsibilities and authorities are also mentioned as part of the individual process documents of each function. They are very much in line with the JD maintained by HR. Is it mandatory to list down the roles and responsibilities in the individual process documents as its a mandatory section.

Answer:

ISO 9001 and ISO 27001 only require that roles, responsibilities and authorities are assigned and communicated (documenting them is not mandatory), so the organization is free to document them the way it is best for them (as a good practice).

But it is important to note that job description and process documents have different purposes, and by not listing down the roles and responsibilities in the individual process documents may affect process performance, so you should evaluate this modification before m aking a decision.
These articles will provide you further explanation about documenting roles and responsibilities:
- How to document roles and responsibilities according to ISO 27001 https://advisera.com/27001academy/blog/2016/06/20/how-to-document-roles-and-responsibilities-according-to-iso-27001/
- What to consider in security terms and conditions for employees according to ISO 27001 https://advisera.com/27001academy/blog/2018/05/23/what-to-consider-in-security-terms-and-conditions-for-employees-according-to-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 06, 2019

Jun 06, 2019

Suggested Topics

Guest user Created:   Oct 23, 2023 ISO 27001 & 22301
Replies: 1
0 0

Toolkit documents

Guest user Created:   Sep 19, 2022 ISO 27001 & 22301
Replies: 1
0 0

Position Description Question

Guest user Created:   Nov 11, 2020 ISO 27001 & 22301
Replies: 3
0 0

Question about Annex 6.1