Assign topic to the user
Please note that the decision about including or excluding controls needs to be based on the results of risk assessment and applicable legal requirements, and it seems neither of you took these into consideration.
So, our recommendation for your team is to see first which risks and legal requirements are relevant to your scope, and based on them identify which controls are applicable.
For further information, see:
- Implementation of security controls https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#section16
Comment as guest or Sign in
Jun 07, 2022

