SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Preventive actions in ISO 27001

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Preventive actions in ISO 27001

The old version of the std was referring to preventive actions and the new one no longer (chapter 10).
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
DejanK Jan 12, 2016

The 27000:2013 refers to preventive actions as “an action aimed at getting rid of a potential noncompliance”. But no trace of “preventive” in 27001:2013. But in my opinion, there is no such thing as a potential noncompliance.
Or you detect it and then it is a detected noncompliance requiring a corrective action. Or you do not detect it and then it has no existence.

Answer: It is true that in ISO 27001:2013 there are no requirements for preventive actions, however preventive actions are in fact included in risk assessment and treatment because the essence of risk management is to recognize a potential problem before it happens, and by treating it to prevent such an incident from happening.

There are examples of potential noncompliance - e.g. if the top management is not investing enough in training and awareness, the nonconformit ies will not happen right away, they will happen in the future. Therefore, in this case the preventive action would be to invest more in training and awareness.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics

Guest user Created:   Nov 05, 2019 ISO 27001 & 22301
Replies: 1
0 0

Video tutorial content

Guest user Created:   Feb 15, 2023 ISO 27001 & 22301
Replies: 1
0 0

Ransomware recovery plan