Expert Advice Community

Guest

Policies and procedures development

  Quote
Guest
Guest user Created:   Dec 20, 2016 Last commented:   Dec 20, 2016

Policies and procedures development

I have started filling in the Policies and procedures as given in the tool kit, but I cannot figure out as to what are the policies and procedure that would require direct input from other departments.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 20, 2016

I mean at this initial stage without having gone through all the documents in details, how can I identify which documents would need direct involvement and input from the other departments in the scope? So that I could fill in those policies and procedures first and dispatch those to the concerning departments under scope, so that they could start sending me the inputs? (i.e. assets list etc etc).

Answer:
By reading the section one of each document (Purpose, scope and users) you can realize who to ask for information. For example for Backup policy (and other templates addressing information technology), you will need to ask the IT department, for Supplier Security Policy policy, you should ask your Procurement department.

By the way , in the video tutorials that come with the toolkit, you will see practical examples about to who should provide input for policies and procedures.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 20, 2016

Dec 20, 2016