SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Filling templates

  Quote
Guest
Guest user Created:   Feb 08, 2019 Last commented:   Feb 08, 2019

Filling templates

1. Regarding the reference docs; what do we need to put in here? Do we need an actual list and if so do we need to list the whole toolkit?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 08, 2019

Answer: Besides the reference to the ISO 27001 standard and to the implementation project plan (if such document exists) that is already included, you have to include reference to any laws, regulations or contracts that have clauses that can impact on your ISMS (e.g., confidentiality clauses on service level agreements with customers, data protection clauses on laws you are enforced to follow, etc.). For this list you can reference the List of Legal, Regulatory, Contractual and Other Requirements template, that is included in your toolkit on folder 02 Procedure for Identification of Requirements, and include the references to all documents there.

There is no need to include reference to any other document from the toolkit.

2. We have an offshore wholly owned subsidiary in India which operates as a separate legal entity, can we include that in the scope?

Answer: Subsidiaries legally bounded to the main organization can be included in the ISMS scope, but you should evaluate if the effort to maintain two organizations operating on different countries in a single scope is not greater than adopting two separated scopes.

3. During the first audit, the auditor mentioned we needed a 'small scope' that would be printed on the ISO Certificate, which part of the scope is he referring to?

Answer: The auditor is referring to a summary from subsections 3.1 to 3.5 of the ISMS Scope Document (processes and services, organizational units, locations, networks and IT infrastructure and the exclusions of the scope). An example may be:

"The ISMS scope comprises of software development process, performed by our software development department on premises located on address xyz, and the customer support process, performed by our customer relationship department on premises located on address abc."

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 08, 2019

Feb 08, 2019

Suggested Topics

Guest user Created:   Jan 28, 2020 ISO 27001 & 22301
Replies: 1
0 0

Filling templates

Guest user Created:   Dec 04, 2018 ISO 27001 & 22301
Replies: 1
0 0

Filling templates

Guest user Created:   Oct 31, 2018 ISO 27001 & 22301
Replies: 1
0 0

Filling templates