Expert Advice Community

Guest

SoA and Risk Treatment Plan

  Quote
Guest
Guest user Created:   Aug 09, 2017 Last commented:   Aug 09, 2017

SoA and Risk Treatment Plan

Regarding the mandatory documents required for ISO27001, does the statement of applicability constitute the risk treatment plan or is the risk treatment plan a completely separate document?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Aug 09, 2017

Answer: They are completely separated documents. The Statement of Applicability documents which security controls are applicable, justification for inclusions, whether they are implemented or not, and the justification for exclusions of controls from Annex A, while the risk treatment plan documents which security controls you need to implement, who is responsible for them, what are the deadlines, and which resources are required.

These articles will provide you further explanation about Statement of Applicability and Risk Treatment Plan:
- The importance of Statement of Applicability for ISO 27001 https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/
- Risk Treatment Plan and risk treatment process – What’s the difference? https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#treatment

These materials will also help you regarding Statement of Applicability and Risk Treatment Plan:
- Book ISO 27001 Risk Management in Plain English
https://advisera.com/books/iso-27001-annex-controls-plain-english/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0
Guest
brianhopla Aug 09, 2017

Thanks for the advice; I thought that was the case.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 09, 2017

Aug 09, 2017

Suggested Topics