SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Query pertinent to mapping controls of the revised standard to the old standard

  Quote
Guest
Guest post Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Query pertinent to mapping controls of the revised standard to the old standard

Hi I have a query pertinent to mapping few controls of the revised standard to the old standard. On understanding the relevant sections, I find that: #9.2.3 Management of privileged access rights does NOT appropriately map to #11.2.3 User password management as given in the mapping document of the revised standard. The two sections are not in sync to be mapped on a one-to-one basis. #9.2.4 Management of secret authentication information of users does NOT appropriately map to #11.2.4 Review of user access rights as given in the mapping document of the revised standard. Again, the two sections are not in sync to be mapped on a one-to-one basis. Please help me clarify my understanding.
0 0

Assign topic to the user

ISO 27001 FOUNDATIONS COURSE

Everything you need to know about ISO 27001.

ISO 27001 FOUNDATIONS COURSE

Everything you need to know about ISO 27001.

Guest
DejanK Jan 12, 2016

Vinay,

I'm not sure to which mapping document you refer to, because we didn't publish such document.

In any case, 2013 revision control A.9.2.3 "Management of privileged access rights" maps to A.11.2.2 "Privilege management" control from 2005 revision.

2013 revision control A.9.2.4 "Management of secret authentication information of users" maps to A.11.2.3 "User password management" from 2005 revision.

Quote
0 0
Guest
Guest post Jan 12, 2016

Thank you Dejan!
That does clarify my understanding.

Also, if I may ask, is it a mandate to follow and implement each and every control in the 'implementation guidance' for a particular control objective/ clause?
Since they are more flexible or more stringent in some domains as compared to the old standard, will the certifying body weigh emphasis on the control objective being met or the several controls listed in the implementation guidance which assist to met the control objective?

Quote
0 0
Guest
DejanK Jan 12, 2016

Vinay,

ISO 27001 does not mention "implementation guidance" - are you perhaps referring to ISO 27002?

In any case, ISO 27002 is irrelevant to certification auditors. For ISO 27001, you have to select only those controls where there are risks or where there are some other requirements (like legal or regulatory) which require you to implement particular control.

To learn more about the risk assessment process and selecting the controls read this article: ISO 27001 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016