SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Information Security Policy

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Information Security Policy

What is the difference between the clause 5.2 and A.5.1.1 and A.5.1.2 controls?
0 0

Assign topic to the user

ISO 27001 INFORMATION SECURITY POLICY

Define the main rules for information security management.

ISO 27001 INFORMATION SECURITY POLICY

Define the main rules for information security management.

Guest
AntonioS Jan 12, 2016

In the new ISO 27001:2013, clause 5.2 and A.5.1.1/A.5.1.2 controls are refer to the same thing: Information Security Policy. But, clause 5.2 describes the top-level Information security policy, while controls A.5.1.1 and A.5.1.2 speak about detailed security policies that cover certain areas of information security. Please, read this article for more information “One information Security Policy, or several policies”: https://advisera.com/27001academy/blog/2013/06/18/one-information-security-policy-or-several-policies/

 

What is your recommendation to record that employees were aware of the policies and other ISMS documents? 

 

Answer:

There are several ways, but I recommend you to perform training sessions (inviting to all staff). In this sessions you can present the ISMS, requirements, documents, records, etc. For each session, you can have a physical document with signature of attendance of all people. After each session, also you can d evelop a small test to evaluate the awareness of each employee (their results is a evidence). If you need information on how to perform training and awareness for ISO 27001, please read this article “How to perform training & awareness for ISO 27001 and ISO 22301”: https://advisera.com/27001academy/blog/2014/05/19/how-to-perform-training-awareness-for-iso-27001-and-iso-22301/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016