SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

ISO 27001 controls (SOA)

  Quote
Guest
Guest user Created:   May 11, 2020 Last commented:   May 14, 2020

ISO 27001 controls (SOA)

1. Would you mind please explaining to me how can we justify the inclusion/exclusion of controls in the SOA?

2. And how can we justify the exclusion of a part of SMSI from the scope?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 11, 2020

1. Would you mind please explaining to me how can we justify the inclusion/exclusion of controls in the SOA?

First is important to note that all controls from ISO 27001 Annex A must be included in the SoA. The justifications are related to applying them or not.

Considering that, broadly speaking, justifications to apply the control or not are based on:

  • results of risk assessment (e.g., there are relevant risks that are handled by applying the control/there are no relevant risks requiring the application of the control)
  • legal requirements (e.g., laws, contract, or regulations) (e.g., there are legal requirements requiring the application of the control / there are no legal requirements requiring the application of the control)
  • top management decision (control is considered applicable by top management as a good practice/control is not applicable by top management decision)

These articles will provide you a further explanation about risk management and SoA:

This material can also help you:

2. And how can we justify the exclusion of a part of SMSI from the scope?

Please note that ISO 27001 does not require justification for exclusions from the ISMS scope. You only need to ensure that the exclusion does not conflict with the requirements of interested parties, and external and internal issues relevant to the ISMS purpose and its intended outcome.

These articles will provide you a further explanation about the scope definition:

This material will also help you regarding scope definition:

Quote
0 0
Guest
Guest May 14, 2020

Thank you for this detailed explanation, I have a specific question : can we justify an exclusion of a control by the fact that the topic of this control is out of scope ? Example : development policy not applicable because development is not performed in ISMS scope. Can we have that in the SOA ?

Quote
0 0
Expert
Rhand Leal May 14, 2020

It is possible to use such justification for the exclusion of control, but please note that common understanding is that information in the SoA refers to elements that are part of the ISMS scope, and such justification (referring to elements, not in the ISMS scope) would only add unnecessary complexity to your document (e.g., an auditor would have to work again on the ISMS scope document to confirm that the development process is out of the scope).

It is simpler to say that the control is not applicable because there are no relevant risks and/or legal requirements demanding the implementation of the control.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 11, 2020

May 14, 2020

Suggested Topics