SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

ISO 27001 clause 6.1.2.c.1

  Quote
Guest
Guest user Created:   Mar 29, 2019 Last commented:   Mar 29, 2019

ISO 27001 clause 6.1.2.c.1

Could you please so kind to advise me in following:
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 29, 2019

6.1.2 The organization shall define and apply an information risk assessment process that: c) identifies the information security risks
1) apply the information security risk assessment process to identify risks associated with the loss of confidentiality, integrity and availability for Information within the scope of the information security management system

This is the only clause in the ISO 27001 which I absolutely do not understand. Could you be so kind and give me a hint or explanation in β€˜ human English β€˜ πŸ˜„. My problem is that, for internal auditing purposes, I want to draft some β€˜ audit-questions ' with reference to this clause but as I do not understand that β€˜ beyond human imagination english of the ISO-guys β€˜ I don’t manage to formulate the right audit question(s) with reference to subclause 6.1.2.c.1.

Answer:

Translating this clause to plain English, what you should question is:
1 - were information security risks identified?; and
2 - are the identified information s ecurity risks related to the information your organization want to protect?

For example:
- if you do not find a Risk Assessment Table, or similar document, then you would have a non-compliance here, since there is no evidence that risks related to the ISMS scope were identified.
- if you find a Risk Assessment Table with risks related to a software development process, and your ISMS scope is about your Customer Management process, then you would have a non-compliance here, since the identified risks are not related to the defined ISMS.

By the way, included in your toolkit there is an Internal Audit Checklist where you can find questions which cover clause 6.1.2.

These materials will also help you regarding internal audit:
- ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-guide/
- ISO 27001:2013 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 29, 2019

Mar 29, 2019

Suggested Topics