SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Information Security Policy vs IT Security Policy

  Quote
Guest
Guest user Created:   Jun 05, 2020 Last commented:   Jun 05, 2020

Information Security Policy vs IT Security Policy

My company has purchased your workshop and documentation toolkit for the ISO 27001 Implementation. We are working on the documents and the statement of Applicability is posing a real challenge.

One thing though I want to be clear on, in your documentation, folder 02 (General policies), I see the information security document which is a relatively short document and not very detailed. However, in the statement of Applicability, I see reference is made many times to the IT Security Policy, which means it should be quite an extensive document.

Please is the Information Security Policy the same as the IT Security Policy?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jun 05, 2020

Please note that these are different documents:

  • the Information Security Policy is located on folder 02 (General policies), as you mentioned
  • the IT Security Policy is located on folder 08 Annex A Security Controls, subfolder A.8 Asset Management

The purpose of the Information Security Policy is to define high-level information about how information security is managed, while the purpose of the IT Security Policy is to provide details on how to use the information system and other information assets.

In the List of Documents file included in your toolkit, you can identify where each document is located and which clauses and controls are covered by each of them.

This article will provide you a further explanation about the information security policy:

Quote
0 1

Comment as guest or Sign in

HTML tags are not allowed

Jun 05, 2020

Jun 05, 2020