SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Filling templates

  Quote
Guest
Guest user Created:   Oct 31, 2018 Last commented:   Oct 31, 2018

Filling templates

1. Do I need to leave the basic outline in the version history or can I start with my own first draft (of course not touching the copyright, but does version 0.1 need to stay)?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Oct 31, 2018

Answer: The data related to "version 0.1" in the history section is only for exemplification purposes. You can change this information for your own.

2. The Risk Assessment of course is the bulk of the questions from asset owners. Some are clear such as physical equipment. Some are less obvious, for example SaaS software common these days such as CRM software, GoogleSuite, Office365 etc - do each of these get listed as a separate asset with a separate owner, or can each be listed with a central asset owner. The permutations will very rapidly end up with hundreds of assets for our 5 person company, with then thousands of Risk (by threat and vulnerability). Would you have any samples for very small start-up companies with < $1M in revenues and all assets are cloud based (SaaS, AWS, personal compute devices etc.)? I plan to do all the heavy lifting as much a s possible and will interview the other employees. Answer: ISO 27001 does not prescribe how the inventory of assets should be developed, so you can use the organization that better fits your needs. Some suggestions are:
- Organize by SaaS provider (e.g., Google applications, Microsoft applications, etc.)
- Organize by purpose (e.g., HR applications, Collaborative applications, etc.)

The most important tip here is that you have to simplify the process by grouping similar assets.
Regarding the designation of assets owners the same applies (you can have one person responsible for all related assets, one for each asset, or a mixed approach). If several users across the company are using particular software or SaaS, then the most senior of them can be the asset owner.

About sample of assets, in this template you have a sheet with a catalogue of assets.

This article will provide you further explanation about inventory of assets:
- How to handle Asset register (Asset inventory) according to ISO 27001 https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Oct 31, 2018

Oct 31, 2018

Suggested Topics

Guest user Created:   Jan 28, 2020 ISO 27001 & 22301
Replies: 1
0 0

Filling templates

Guest user Created:   Feb 08, 2019 ISO 27001 & 22301
Replies: 1
0 0

Filling templates

Guest user Created:   Dec 04, 2018 ISO 27001 & 22301
Replies: 1
0 0

Filling templates