SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Question about mandatory documentation

  Quote
Guest
Guest user Created:   Nov 04, 2020 Last commented:   Nov 04, 2020

Question about mandatory documentation

in the White paper: Checklist of Mandatory Documentation Required by  ISO/IEC 27001 (2013 Revision) the Supplier Security Policy is market mandatory, but List_of_documents_ISO_27001_ISO_22301_Premium_Documentation_Toolkit_EN.pdf marks only A.15.2 Security Clauses for Suppliers and Partners mandatory? Am I reading this right? My customer wants combine Supplier Security Policy to another document and that’s why I’m asking.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 04, 2020

First of all, thanks for this feedback

Indeed in the List of documents file the Supplier Security Policy should be marked as mandatory, but with an asterisk, because it is related only to controls from ISO 27001 Annex A, which are only required if there are relevant risks, or legal requirements, that demands the implementation of the related controls. We'll make this correction ASAP.

Regarding the need of your customer, he can combine the Supplier Security Policy with another document.

Quote
0 1

Comment as guest or Sign in

HTML tags are not allowed

Nov 04, 2020

Nov 04, 2020

Suggested Topics

Guest user Created:   Apr 09, 2022 ISO 27001 & 22301
Replies: 2
0 0

Question about toolkit

Guest user Created:   Jun 29, 2021 ISO 27001 & 22301
Replies: 1
0 0

Question about A.7.1.2