SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Documents missing in toolkit

  Quote
Guest
Guest user Created:   Apr 05, 2023 Last commented:   Apr 06, 2023

Documents missing in toolkit

Can you please advise if there are some documents that cover vulnerability management, or exception management.

It was nt possible to find "vulnerability management, or exception management" in the toolkit.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 05, 2023

There is no template covering specifically vulnerability management because the standard does not require this control to be documented.

Please note that Advisera's ISO 27001 Documentation Toolkit does not have a document for each and every control from ISO 27001 because of the following reasons:

    1. ISO 27001 does not require each and every control to be documented

    2. If the toolkit had a document for each control, there would be too many documents, and this would be an overkill for smaller and mid-size companies.

Since our target are SMEs, we have decided to include an optimum amount of documents for companies of this size - the toolkit includes:

  • All the mandatory documents - e.g., Information Security Policy, Statement of Applicability, Risk Assessment Methodology, Access Control Policy, etc.
  • Documents that are not mandatory, but are commonly used - e.g. BYOD Policy, Classification Policy, Password Policy, Backup Policy, etc.

In case you identify you really need to apply control A.8.8 (Management of technical vulnerabilities), you can contact our support by email, or on scheduled online meeting (https://advisera.com/27001academy/consultation/), so one of our experts can help you on how to better evidence this control implementation.

For further information, see:

Quote
0 0
Guest
Guest user Apr 06, 2023

I understand that but exception management and vulnerability management are the basic controls which we need to have a policy created.
Please help me with this.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 05, 2023

Apr 06, 2023

Suggested Topics