Expert Advice Community

Guest

Exclusion of controls

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Exclusion of controls

 Which controls from Annex A can be excluded, if my organization:
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
AntonioS Jan 12, 2016

1. doesn't have any e-commerce activities
2. doesn't have internal software development activities. There are an internal IT department, but software development is externalized.

 

Answer:

Point 1: In the ISO 27001:2013 there is no control directly related to e-commerce. You can find the control “A.14.1.3 Protecting application services transactions” but it can be for any transactions, not only related to e-commerce. 
 
Point 2: In principle you can exclude all controls related to the “A.14.2 Security in development and support processes”: A.14.2.1 Secure development policy, A.14.2.2 System change control procedures. Etc.
 
Keep in mind that the exclusion of controls can be made only after the risk assessment is finished. 
 
Finally, I recommend you to read this article "The basic logic of ISO 27001: How does information security work?" : https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics

Guest user Created:   Apr 24, 2023 ISO 27001 & 22301
Replies: 1
0 0

Query on ISO 27001:2022 SOA

Guest user Created:   May 11, 2020 ISO 27001 & 22301
Replies: 3
0 0

ISO 27001 controls (SOA)

Guest user Created:   May 08, 2020 ISO 27001 & 22301
Replies: 1
0 0

Question about SOA