Expert Advice Community

Guest

Is the requirement/business related to information security need to be identify?

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Is the requirement/business related to information security need to be identify?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
AntonioS Jan 12, 2016

Is the requirement/business related to information security need to be identify? Or only customer name?
If let say I have 100++ customer contract or more so I need to identify all of them to find which requirement related to information security? Look many.
 

Answer:

If you have standardized contracts with your customers, and therefore the same security clauses in each contract, you can list all the customers as one item only, specifying security clauses. If not, you need to identify the name of your customers (only those that are relevant), and requirements for each one (but only requirements relevant to information security). This is so, because the standard establishes in the clause 4.2 a) “The organization shall determine interested parties that are relevant to ISMS” and in the clause 4.2 b) “The organization shall determine the requirements of these interested parties…”
I think that if you consider only relevant clients that are relevant to the ISMS (think only in those which can influence the security of the information within your ISMS scope), you can reduce your list. 
Remember that we have a procedure for the identification of requirements that can help you. You can see a free version clicking on “Free Demo” tab here “Procedure for Identification of Requirements” : https://advisera.com/27001academy/documentation/procedure-for-identification-of-requirements/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016