SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Integrated Management System

  Quote
Guest
Guest user Created:   Apr 30, 2020 Last commented:   Apr 30, 2020

Integrated Management System

My company has taken an integrated approach to ISO 27001, 9001 and 22301. I have 2 questions:

1. We have integrated the 3 risk registers and have been having monthly risk meetings but we would like to find out how often would the SOA change from the ISO 27001 perspective?  Would it be after each risk meeting?  What happens if a control has been implemented and another risk is identified to the same control? 

2. We are approaching our surveillance audit soon and would like to find out what an auditor would typically look out for during the surveillance audit.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 30, 2020

1. We have integrated the 3 risk registers and have been having monthly risk meetings but we would like to find out how often would the SOA change from the ISO 27001 perspective?  Would it be after each risk meeting?  What happens if a control has been implemented and another risk is identified to the same control? 

 ISO 27001 does not prescribe how often the SoA should change, but you should consider updating the SoA every time there is a need for significant change in applicable controls (e.g., a new control is included, a control is excluded from SoA, an implementation method is changed, etc.). This need can come not only from risk meetings but also from management review, non-conformity treatment, etc.

In case a control has been implemented and another risk is identified to the same control, you have to evaluate the impact of not treating this risk until the next planned review of the implemented control to decide if an early change is needed.

For further information:

2. We are approaching our surveillance audit soon and would like to find out what an auditor would typically look out for during the surveillance audit.

The surveillance audit is performed the same way as a certification audit. The difference is that it covers only part of the ISMS scope (evidence of the fulfillment of the mandatory requirements and of part of the applicable controls in a sample of the process in the ISMS scope).

These materials will provide you a further explanation about surveillance audits:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 30, 2020

Apr 30, 2020