Expert Advice Community

Guest

Security measures

  Quote
Guest
Guest user Created:   Feb 25, 2016 Last commented:   Feb 25, 2016

Security measures

The measures that are in this form should be determined by the customer, for example to what scope the customer wants to be certified. Or should the measures be determined by the certification body?
0 0

Assign topic to the user

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

Guest
Antonio Jose Segovia Feb 25, 2016

The question is related to this article which speaks about the Statement of Applicability, so the form he mentions is Statement of Applicability: https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/

Answer:
I suppose that you mean “security measures”, if so, these measures should be determined by the company that have implemented ISO 27001 (not by his customer or by his certification body), and you only need to implement the measures that are necessary to reduce the risks identified during the risk assessment & treatment. So, in the SOA you will need to apply only the security measures that are necessary to reduce the risks identified.

By the way, you will complete the SOA after the risk treatment, but before the risk treatment plan. Do you want more information about the steps of t he risk assessment treatment? This article can be interesting for you “ISO 27001 risk assessment & treatment – 6 basic steps” : https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/

This article can be also interesting for you “Risk Treatment Plan and risk treatment process – What’s the difference?” : https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#treatment

Finally, do you know our online course? “ISO 27001:2013 Foundations Course” : https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 25, 2016

Feb 25, 2016

Suggested Topics