SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk treatment plan vs Statement of applicability

  Quote
Guest
Guest user Created:   May 03, 2020 Last commented:   May 03, 2020

Risk treatment plan vs Statement of applicability

trying to understand the difference between the risk treatment plan and the statement of applicability.  Shouldn’t one document show what controls need to be implemented, seems like the purpose is the same.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 03, 2020

Please note that the statement of applicability presents a summary of which controls are necessary, the justification for their inclusions, whether they are implemented or not, and the justification for exclusions of controls from Annex A, while the risk treatment plan documents which actions are necessary to implement the security controls you need, who is responsible for them, what are the deadlines, and which resources are required.

In short, the purpose of the SoA is to describe the security profile of a company, while the purpose of the RTP is to define implementation responsibilities. 

These articles will provide you a further explanation about the Statement of Applicability and Risk Treatment Plan:

These materials will also help you regarding Statement of Applicability and Risk Treatment Plan:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 03, 2020

May 03, 2020