Expert Advice Community

Guest

Implementation alternatives

  Quote
Guest
Guest user Created:   Jul 06, 2017 Last commented:   Jul 06, 2017

Implementation alternatives

Dear Dejan, thanks for your email. I'm currently project manager for XXXXX responsible for achieving GDPR compliance and ISO 27001 accreditation. If you don't mind I've a question for you. What order would you progress these two projects? GDPR on it's own because of the known date for the regulation coming into force or ISO 27001 accreditation knowing this will deliver an environment which satisfies GDPR? I value your opinion.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 06, 2017

Answer: The first thing you should consider is the duration of your ISO 27001 implementation project and the deadline for EU GDPR compliance. If your project can be concluded before the deadline maybe it is better to start with ISO 27001 because, as you said, it can deliver an environment which satisfies GDPR and other requirements your organization may have for the ISMS.

If your project cannot be finished before the deadline, you should consider if a reduction in the certification scope, e.g. to cover only the part of the original scope that would be related to EU GDPR, can allow you to meet the deadline, and if post poning the implementation of the remaining scope is acceptable (since the management part of the system will be already implemented you will have less activities to perform).

If none of these alternatives are acceptable, then you should consider going first for EU GDPR compliance, and after that make arrangements in the ISO 27001 implementation project to include those controls in the system.

This articles will provide you further explanation about ISO 27001 projects:
- ISO 27001 project – How to make it work https://advisera.com/27001academy/blog/2013/04/22/iso-27001-project-how-to-make-it-work/
- Does ISO 27001 implementation satisfy EU GDPR requirements? https://advisera.com/27001academy/blog/2016/10/17/does-iso-27001-implementation-satisfy-eu-gdpr-requirements/

These materials will also help you regarding ISO 27001 projects:
- Preparations for the ISO Implementation Project: A Plain English Guide https://advisera.com/books/preparations-for-the-iso-implementation-project-a-plain-english-guide/
- Seven key problems to avoid in ISO 27001 implementation [free webinar] https://advisera.com/27001academy/webinar/seven-key-problems-to-avoid-in-iso-27001-implementation-free-webinar-on-demand/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 06, 2017

Jul 06, 2017

Suggested Topics

Guest user Created:   Jan 09, 2019 ISO 27001 & 22301
Replies: 1
0 0

Implementation alternatives

Guest user Created:   Nov 19, 2016 ISO 27001 & 22301
Replies: 1
0 0

Risk treatment options