SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Documents considered as next-level projects

  Quote
Guest
Guest user Created:   Nov 05, 2021 Last commented:   Nov 05, 2021

Documents considered as next-level projects

Hello Dejan, Thank you for meeting with me on Friday. As you mentioned during the meeting, the following documents should be considered as next-level projects since they are not needed for our company. Am I correct in that assumption? 04.2_Cloud_Security_Policy_Cloud_EN.docx 04.3_Policy_for_Data_Privacy_in_the_Cloud_Cloud_EN.docx Furthermore, I would appreciate it if you could see the attached and tell me which step you mentioned is not applicable to us? (If any)
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 05, 2021

1 - As you mentioned during the meeting, the following documents should be considered as next-level projects since they are not needed for our company. Am I correct in that assumption?

04.2_Cloud_Security_Policy_Cloud_EN.docx

04.3_Policy_for_Data_Privacy_in_the_Cloud_Cloud_EN.docx

If you want to be compliant with ISO 27001 only, and not with ISO 27017 and ISO 27018, the 2 documents you mentioned are not needed; also in the Statement of Applicability, you need to take into account only the 114 controls that are related to ISO 27001.

2 - Furthermore, I would appreciate it if you could see the attached and tell me which step you mentioned is not applicable to us? (If any)

Please note that to implement ISO 27001 you will have to go through all the folders listed in the toolkit. By consulting the List of Documents file that comes with your toolkit you will identify which documents need to be implemented to fulfill standards requirements (e.g., Information, Security Policy, SoA, etc.), and those that are recommended to be implemented because they are considered as good practice (e.g., Procedure for Corrective Action).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 05, 2021

Nov 05, 2021

Suggested Topics

Brad Created:   Apr 22, 2024 ISO 27001 & 22301
Replies: 1
0 0

Custom Edit Documents

Guest user Created:   Oct 23, 2023 ISO 27001 & 22301
Replies: 1
0 0

Toolkit documents