Hi Advisera Team!
For controls that are applicable for us based on risk assessment, do we need to implement them as stated in ISO 27002, or can we interpret them ourselves? When it should be strict according to ISO 27002, then do we have to implement everything what stays there with the word "shall"?
Thank you for your help!
Assign topic to the user
Please note that ISO 27002 is a support standard that provides guidelines and recommendations for implementation of ISO 27001 Annex A controls, so it is not mandatory, and you can adapt its contents to your context, provided you fulfill the security objectives and security controls statement provided in the ISO 27001 Annex A.
Regarding the word “shall”, please note that ISO 27002, as a guideline, does not use the word “shall”, but “should”, and that for ISO world means that its content can be implemented or not, according to your needs.
This article will provide you a further explanation about ISO 27002:
- ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
These materials will also help you regarding controls from Annex A:
- ISO 27001 Annex A Controls in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- ISO 27001 Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Feb 10, 2021