SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Fulflling control A.18.1.1

  Quote
Guest
Guest user Created:   Jul 03, 2018 Last commented:   Jul 03, 2018

Fulflling control A.18.1.1

Hi there, I have a few questions regarding completing (clause A.18.1.1) the list of Statutory, regulatory, and contractual requirements. Could you help me out with the following?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 03, 2018

1 - Does Contractual requirements refer to any contract or service agreement we have made with a supplier; for example telecommunications, web hosting?

Answer: Contractual requirements refer to any contract or service agreement relevant to information security, established not only between your organization and suppliers, but with customers and employees too.

This article will provide you information about what to consider as contractual requirements:
- Which security clauses to use for supplier agreements? https://advisera.com/27001academy/blog/2017/06/19/which-security-clauses-to-use-for-supplier-agreements/
- What to consider in security terms and conditions for employees according to ISO 27001 https://advisera.com/27001academy/blog/2018/05/23/what-to-consider-in-security-terms-and-conditions-for-employees-according-to-iso-27001/

2 - Should the list of re gulatory and legal requirements include those required by our clients? For example the Civil Contingencies Act needed for an emergency service or local council we would be providing a serve to.

Answer: Regulatory and legal requirements relevant to information security must consider requirements from any relevant interested party, such as customers, suppliers, regulators, governments, etc.
This article will provide you information about interested parties and their requirements:
- How to identify interested parties according to ISO 27001 and ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-identify-interested-parties-according-to-iso-27001-and-iso-22301//
- How to identify ISMS requirements of interested parties in ISO 27001 https://advisera.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 03, 2018

Jul 03, 2018