Expert Advice Community

Guest

Filling templates

  Quote
Guest
Guest user Created:   Dec 04, 2018 Last commented:   Dec 04, 2018

Filling templates

We've purchased your toolkit and I'm having some issues to fill out the document for List of Legal Regulatory Contractual and Other Requirements. Could you please give me some guidance on it? What I actually need is some explanation about how to fill this out. I've listed the interested parties but I'm confused about the other columns. What exactly should I put on: Requirement, Document stipulating the requirement, Person responsible for compliance andDeadlines?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 04, 2018

Answer:

Since you already have identified the interested parties, now you have to identify the documents in which their requirements can be located (e.g. service level agreements, outsourcing contracts, laws, industry regulations, etc.), and the precise requirements that must be fulfilled (e.g., the clauses).

For example, a customer has a service level agreement with your company which defines, on clause 32-b, that access to all information provided by the customer to information system ABC are restricted to customer personnel only. In this case the person responsible for syste m ABC is the responsible to ensure compliance of the system to this requirement. Then your document would be like this:

Interested party: Customer Jon
Requirement: Clause 32-b (Information provided to system ABC are restricted to customer's personnel)
Document: Service level agreement
Person responsible for compliance: System ABC administrator
Deadline: when system ABC is made available for customer use

This article will provide you further explanation about identifying requirements:
- How to identify ISMS requirements of interested parties in ISO 27001 https://advisera.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 04, 2018

Dec 04, 2018

Suggested Topics

Guest user Created:   Jan 28, 2020 ISO 27001 & 22301
Replies: 1
0 0

Filling templates

Guest user Created:   Feb 08, 2019 ISO 27001 & 22301
Replies: 1
0 0

Filling templates

Guest user Created:   Oct 31, 2018 ISO 27001 & 22301
Replies: 1
0 0

Filling templates