Assign topic to the user
Answer: You assumption is right concerning controls that are to be implemented, or aren't to be, considering the results of risk assessment. But you also have to remember that you may have some controls already implemented before the ISMS implementation practice, either because you adopted them as a market practice, or a contract or legal requirement required you to do so. So, some controls can already be stated as implemented during the implementation of the risk treatment plan.
This article will provide you further explanation about SOA:
- The importance of Statement of Applicability for ISO 27001 https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/
Thes e materials will also help you regarding SOA:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Jun 09, 2017