Implementing regulatory requirements against cyber-threats
Assign topic to the user
Answer:
When implementing regulatory requirements overall points you must focus on are:
- identification of which requirements you must comply to, so you can map requirements that must be fulfilled, related cyber-threats, and required controls (this will save you time, effort and costs).
- prioritization of requirements implementation, considering related cyber-threats, needed resources and impacts of non compliance.
- records you need to gather to evidence the requirements are fulfilled.
This article will provide you further explanation about controls implementation:
- 8 criteria to decide which ISO 27001 policies and procedures to write https://advisera.com/27001academy/blog/2014/07/28/8-criteria-to-decide-which-iso-27001-policies-and-procedures-to-write/
Comment as guest or Sign in
May 17, 2019