Expert Advice Community

Guest

Identification of Requirements - level of detail?

  Quote
Guest
Guest post Created:   Jan 13, 2016 Last commented:   Jan 13, 2016

Identification of Requirements - level of detail?

Hi I'm compiling my list of interested parties and their requirements for section 4.2 I have the list of legal/regulatory bodies etc which is very helpful, however I was wondering what level of detail I need to go into? For example, with the Data Protection Act, is it sufficient to include the general principles (e.g. "Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes."), or do I need to specifically include more specific requirements such as, e.g. "those involved in recruitment and selection are aware that data protection rules apply and that they must handle personal information with respect." It seems that if I go into that much detail, it becomes more of a control application than a scope document, so I'm not sure when to stop! Thanks
0 0

Assign topic to the user

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

Guest
AntonioS Jan 13, 2016

From my point of view, in your list of interested parties it is sufficient to include the general principles. Anyway, for ISO 27001 is important that your company comply with all laws and legal regulations, but the detail is not established in the standard. For the level of detail that you need to go into, you will need information about each specific law in your country. For example, for Personal Data protection, in some countries you need to identify all personal data, the level of protection for each personal data, and implement the necessary measures, which usually are defined in the own law.
So, my recommendation is that after the identification of all legal requirements, you need to find information in your country about each law to know specifically what are the requirements (this information about the detail of each law must be public)
Remember that you can find here a list of laws and regulations on information security and business continuity "Laws and regulations on information security and business continuity" : https://advisera.com/27001academy/knowledgebase/laws-regulations-information-security-business-continuity/
Finally, have you seen this interesting article about the identification of interested parties? "How to identify interested parties according to ISO 27001 and ISO 22301" : https://advisera.com/27001academy/knowledgebase/how-to-identify-interested-parties-according-to-iso-27001-and-iso-22301//

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016