Expert Advice Community

Guest

Management decisions

  Quote
Guest
Guest user Created:   Apr 15, 2017 Last commented:   Apr 15, 2017

Management decisions

I do believe that ISO 27001 is really helpful but i have my doubts because in a small company where the decision are made by the owner, and even though the company has to follow trouth the process and controls, if the manager just wants something faster than usual and the business is not in any danger at all, he can made the decision of break the process or the control. So how an small company can overcome this?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 15, 2017

Answer: Considering ISO 27001, top management can previously define under which circumstances can the rules (i.e., processes or controls) be bypassed, and must ensure that relevant information related to those decisions are recorded (e.g., a risk assessment). If you can provide such circumstances and evidences the situation is ok.

The situation you should be worried about is if bypass situations happen often, because this would means that the information security management system is not properly aligned with business expected outcomes, and that is a problem, generally related to the perception of the risks the organization is will ing to take, also called risk appetite. I this case, what top management can do is to change policies or procedures as they think is needed.

This article will provide you further explanation about risk appetite:
- Risk appetite and its influence over ISO 27001 implementation https://advisera.com/27001academy/blog/2014/09/08/risk-appetite-influence-iso-27001-implementation/

These materials will also help you regarding risk appetite:
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 14, 2017

Apr 14, 2017

Suggested Topics

Gerry Created:   Sep 18, 2023 ISO 27001 & 22301
Replies: 2
0 0

Risk Treatment Advice