Expert Advice Community

How to align current policies with ISO27001

  Quote
back2thefuture Created:   Nov 11, 2020 Last commented:   Nov 13, 2020

How to align current policies with ISO27001

Dear all,

 

I hope you are all well.

Im hoping someone can point me in the rght direction. We currently have a set of policies that include things like:

- Backup

- Mobile devices

- Encryption

-Information security

-Network security

-Change management

 

How would i start going about aligning these with ISO27001? Is there a process i can follow?

Any help greatly appreciated.

Many thanks

 

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 13, 2020

I'm assuming by your question that you are not considering certification, only compliance with the standard.
 
Considering that, to align the stated policies with ISO 27001 you need to:

  • identify the processes where these policies are used.
  • identify legal requirements (e.g., laws, regulations, and contracts) that impact information security related to the identified processes.
  • perform the risk assessment process, to identify relevant information security risks related to the identified processes.
  • perform risk the risk treatment process, to identify how to treat relevant information security risks and which controls from ISO 27001 Annex A to implement.
  • Identify which controls from ISO 27001 Annex A to implement, based on identified legal requirements.
  • adjust the policies according to the identified controls.

To see how similar policies compliant with ISO 27001 looks like, please see:  

These articles will provide you further information:

These materials will also help you regarding risk assessment and ISO 27001 Annex A controls:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 11, 2020

Nov 13, 2020