Expert Advice Community

Guest

ISO 27017, ISO 27018 and ISO 27001

  Quote
Guest
Guest user Created:   Nov 03, 2017 Last commented:   Nov 03, 2017

ISO 27017, ISO 27018 and ISO 27001

Do I need to comply with ISO27017 and 18 in order to be compliant with ISO27001? I'm asking to know if I can skip the cloud stuff until I've implemented ISO27001.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 03, 2017

Answer: ISO 27017 and ISO 27108 only provide recommendations and guidelines to the implementation of controls of ISO 27001 Annex A, so their application is not mandatory for an organization to be compliant with ISO 27001.

These articles will provide you further explanation about ISO 27017 and ISO 27018:
- ISO 27001 vs. ISO 27017 – Information security controls for cloud services https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
- ISO 27001 vs. ISO 27018 – Standard for protecting privacy in the cloud https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/

Regarding if you can skip cloud elements until the implementation of ISO 27001, you can only do that if there is no cloud-related elements on your ISMS scope.

These articles will provide you fur ther explanation about scope definition:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/

These materials will also help you regarding scope definition:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 03, 2017

Nov 03, 2017

Suggested Topics