Expert Advice Community

Guest

SoA content

  Quote
Guest
Guest user Created:   Jul 29, 2017 Last commented:   Jul 29, 2017

SoA content

Does the SOA need to contain justification for inclusions, and whether they are implemented or not. I was under the impression only the reason for exclusion is required.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 29, 2017

From the standard, I am not able to gauge whether the above fields are mandatory.

Answer: The justification for inclusions is needed because the reason for applying a control will help understand how to evaluate its effectiveness. For example, if the reason is because results of risk assessment, them we have to check which risks are being treated by the control to ensure all of them are being handled properly. On the other hand, if the reason is because of a legal or contractual requirement, we need to identify if this requirement is being properly fulfilled

You can find the requirements for filling the SoA in the clause 6.1.3 d) of ISO 27001.

This article will provide you further explanation about the Statement of Applicability:
- The importance of Statement of Applicability for ISO 27001 https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/

These materials will also help you regarding the Statement of Applicability:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 29, 2017

Jul 29, 2017

Suggested Topics

Guest user Created:   Nov 22, 2017 ISO 27001 & 22301
Replies: 1
0 0

SoA content_

Guest user Created:   Nov 21, 2017 ISO 27001 & 22301
Replies: 1
0 0

SOA content

Guest user Created:   Sep 17, 2017 ISO 27001 & 22301
Replies: 2
0 1

SOA content fields