Expert Advice Community

Guest

Regulatory compliance

  Quote
Guest
Guest user Created:   Sep 19, 2018 Last commented:   Sep 19, 2018

Regulatory compliance

How to determine the appropriate level of completeness in regulatory identification of a ISMS according to the scope? My doubts is because I found gaps between SOA, scope and a.18.1 controls and I-m not sure how to handle them.
0 0

Assign topic to the user

ISO 22301 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 22301 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 19, 2018

Answer:

To ensure proper identification of regulations related to an ISMS scope in most cases you need expert support, either internal from experienced personnel who work on the processes included in the scope or external from legal consultants. Once these regulations are identified you can identify the clauses that are related to information security, and which security controls are needed to handle these clauses.

You can start by using this list of laws and regulations: Laws and regulations on information security and business continuity https://advisera.com/27001academy/knowledgebase/laws-regulations-information-security-business-continuity/

But please note that this list is not exhaustive.

Quote
0 0
Guest
vivianafernndez Sep 19, 2018

Thank you so much for your answer. As an auditor, if your client's argument is "My only duty according to A.18.1 is to identify and list regulations related with the scope defined to my ISMS", and, if he/her is able to demonstrate that task, should I record that control as a conformity? I.e. the company includes only regulations related with the only one service (in scope) but they didnt list other general regulations, for instance labor laws applying to their employees.

Quote
0 0
Expert
Rhand Leal Sep 20, 2018

If such general regulations do not have impact on the ISMS they can leave them out of the scope and the control would be compliant.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 19, 2018

Sep 20, 2018

Suggested Topics