Expert Advice Community

Guest

Include controls in the SOA

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Include controls in the SOA

 In inclusion of controls in Annex A, what possibly could be the justifications if we cant find any justifications from risk assessment, legal requirement, contractual requirement or business requirement/best practice?
0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

Guest
AntonioS Jan 12, 2016

We included a set of controls from 2005 version, but our SOA apparently didn't have strong justification for inclusion. And now we don't want to exclude those controls in 2013 version but sadly we cant find the strong justification.

Answer:

If there are another purpose for the inclusion of a control, you can include it in the SOA. For example, if you have controls added by ISO 27001:2005, and you don’t want to exclude them, you can include as justification: Included by ISO 27001:2005
Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics

Guest user Created:   Dec 06, 2022 ISO 27001 & 22301
Replies: 1
0 0

Assets

Guest user Created:   Dec 06, 2022 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 Auditor Question