Expert Advice Community

Guest

Risk treatment implementation

  Quote
Guest
Guest user Created:   Aug 27, 2018 Last commented:   Aug 27, 2018

Risk treatment implementation

Now we reached to the planning for risk treatment for ISO 27001. In our statement of applicability we excluded only one of the controls in annex A due to un-applicability. Now the remaining controls are required where some of them already implemented and most of them not implemented yet. We shall include the planning for the implementation in the risk treatment plan but this will mean implementing the control in future date.
0 0

Assign topic to the user

ISO 27001 RISK TREATMENT PLAN

Determine responsibilities for the implementation of controls.

ISO 27001 RISK TREATMENT PLAN

Determine responsibilities for the implementation of controls.

Expert
Rhand Leal Aug 27, 2018

Now we would like to get certified and we are communicating with the certifications companies for the audit and certification. My question is; since we have not yet implemented all the controls, is that a problem? or since we included the implementation in the treatment plan for a future date this is covered? ... In another meaning (if we decided that the Annex A controls should be implemented then is it a must to implement them before getting certified as ISO 27001?

Answer:

You can leave some of the controls for the implementation for after the certification under the following conditions:
1) That you have impleme nted before the certification the controls that mitigate the biggest risks – in other words, you can leave only less important controls for after the certification.
2) That you have specified the deadlines for the controls that you will be implementing after the certification in your Risk Treatment Plan – of course, those deadlines must be after the certification date.
3) That your risk owners or top management accept all the risks for which controls have not been implemented before the certification.

This means that the most important controls must have ”implemented“ status at the certification, while the less important controls can have status ”planned“ or ”partially implemented“ at the moment of the certification. Of course that for controls with status”partially implemented” you have to keep evidences of activities already performed regarding the implementation (the certification auditor won't audit the control, but he will verify if the implementation plan is being executed).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 27, 2018

Aug 27, 2018

Suggested Topics