Expert Advice Community

Guest

Implementation of ISO 27001

  Quote
Guest
Guest user Created:   Apr 29, 2020 Last commented:   Apr 29, 2020

Implementation of ISO 27001

 Do you have a template for a copyright protection policy to meet the requirement of Annex A.18.1.2?

In your pdf list of documents, you point out that A.18 does not exist as a separate folder, but the content for it can be found in the following folders:

02 - Requirements identification process
08, A.8 - Management of values
08, A.10 - cryptography
Unfortunately, we cannot find a template for a guideline for A.18.1.2 in these folders

Can you please help us here and contact an expert?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 29, 2020

The most related document to your need is IT security policy, located on folder 08 Annex A Security Controls >>  Asset management

This template covers control A.18.1.2 by defining rules for protection of Intellectual property rights, both from organization's, and material of third-parties the organization uses.

Please note that ISO 27001 does not require a specific copyright protection policy, and from our experience the control A.18.1.2 covered by the IT Security Policy is enough for the certification purpose.

Quote
0 0
Guest
Jürgen Apr 29, 2020

Hello Rhand Leal

Thank you for your reply!
Our external auditor requested explicitly such a policy and noted the lack as an essential N-C, so if we don't have one, we don't get certified

Quote
0 0
Expert
Rhand Leal Apr 29, 2020

According to ISO 27001 'procedures' can be implemented without writing them down - see this article for more details:

Considering that, if you do not have any specific legal requirement (e.g., law, regulation or contract) demanding you to have a documented copyright protection policy, there is no basis for the auditor to raise a nonconformity, but he can raise an opportunity for improvement for you to consider if it is worthy to have such a policy documented. In case of an opportunity for improvement, you are not obliged to implement and document the policy, provided you give a sound justification to not implementing it (e.g., lack of relevant risks or legal requirements demanding this specific policy).

Quote
0 0
Guest
Jürgen Apr 29, 2020

Hello Rhand Leal

Thank you for your reply. I just wrote one policy. But thanks for your advise and further comments on the subject. Our problem is that the auditor already raised the nonconformity and I don't want to argue with him about this particular policy.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 29, 2020

Apr 29, 2020