Expert Advice Community

Guest

ISO 27001 requirements for controls

  Quote
Guest
Guest user Created:   May 09, 2017 Last commented:   May 09, 2017

ISO 27001 requirements for controls

I just want to check if ISO 27001 procedures require an immediate removal of IT staff's usernames when resignation? the IS audit manager at a local bank ? please note that, I mean the immediate removal before the notice period is done
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 09, 2017

Answer: What ISO 27001 requires is that an organization considers its context and assesses its risks to implement proper controls to bring risks to acceptable levels. So the decision for immediate removal of users access is up to each organization, based on its risk assessments, legal or contractual requirements.

This article will provide you further explanation about access control:
- How to handle access control according to ISO 27001 https://advisera.com/27001academy/blog/2015/07/27/how-to-handle-access-control-according-to-iso-27001/
- The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

These materials will also help you regarding access control:
- Book Secure & Simple: A Small-Bu siness Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 09, 2017

May 09, 2017