Filling a SoA document
Assign topic to the user
Answer: ISO 27001 does not requires responsibilities to be included in the SoA, so you do not need to include this information because of the standard. Some organizations decide to include this information in the SoA so it becomes easier for them to identify who is responsible for each control (all information could be found in a single document). Of course, if you decide for this approach, if a control is considered not applicable, them you should left the field blank.
Comment as guest or Sign in
Aug 05, 2017

