SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Justification in a Statement of Applicability

  Quote
Guest
Guest user Created:   Nov 17, 2016 Last commented:   Nov 17, 2016

Justification in a Statement of Applicability

One of the columns on your Statement of Applicability is “Justification for Selection/Non-Selection”. I understand that generally that column would tie back to a specific item on the risk assessment results, but some of the controls are common sense/normal operating procedure for most companies. As a result, we already had some of these controls in place prior to this project, so they didn’t appear on the risk assessment/risk treatment table, as we’d already eliminated those associated threats. In this instance, how should we “justify” the inclusion of that control. Is it enough to say “already implemented”, or should we try to justify why we implemented them originally?
0 0

Assign topic to the user

ISO 9001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 9001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 17, 2016

Answer: To justify an implemented control that do not have identified risks on the Risk Assessment, that can be related to it, the most suitable justification on the Statement of Applicability would be, as you thought, the original reason that justified the control implementation, something like "control implemented as a requirement of interested parties", or "control considered common sense / normal operating procedure in our industry".

This article will provide you further explanation about risk assessment:
- ISO 27001 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/

This article will provide you further explanation about the Statement of Applicability:
- The importance of Statement of Applicability for ISO 27001 https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/

These materials will also help you regarding risk assessment and SoA:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your
Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course
https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 17, 2016

Nov 17, 2016

Suggested Topics

Guest user Created:   Feb 10, 2021 ISO 9001
Replies: 1
0 0

ISO 9001 Non-conformance justification

Guest user Created:   Oct 02, 2020 ISO 9001
Replies: 1
0 0

Applicability of ISO 9001

Guest user Created:   May 20, 2020 ISO 9001
Replies: 1
0 0

Clause 8.3. applicability