Mandatory policies for ISO 27001
Assign topic to the user
Answer:
Regarding the main clauses of ISO 27001, only the Information Security Policy is required (to fulfill clause 5.2). Regarding Annex A controls, you must consider these policies as mandatory if there are risks which would require their implementation (i.e., controls related to these policies are stated as applicable on the Statement of Applicability):
- Access control policy (if clause A.9.1.1 is applicable on SoA)
- Supplier security policy (if clause A.15.1.1 is applicable on SoA)
The document "11.A. 16_Data_Breach_Response_and_Notification_Procedure_Integrated_EN" is in fact a procedure (its ISO 27001 equivalent is the Incident Management Procedure). It is im portant to note that in the context of ISO 27001 the division between policies and procedures is not very important.
Comment as guest or Sign in
Mar 30, 2019