Referencing to security controls in policies and procedures
Assign topic to the user
Answer:
It is true that we did not reference to particular controls within the text of each security rule, because this is not required by ISO 27001 - sometimes one security rule covers several controls, and sometimes the same control is covered within several security rules, so referencing to the particular control in the text of each security rule would be rather difficult.
Comment as guest or Sign in
Jan 18, 2016

