Expert Advice Community

Guest

SoA content_

  Quote
Guest
Guest user Created:   Nov 22, 2017 Last commented:   Nov 22, 2017

SoA content_

May I ask to which extent should be a Share risk situation detailed in SoA?
0 0

Assign topic to the user

ISO 27001 STATEMENT OF APPLICABILITY

List all controls and determine which are applicable and why.

ISO 27001 STATEMENT OF APPLICABILITY

List all controls and determine which are applicable and why.

Expert
Rhand Leal Nov 22, 2017

Just taking as example the HR security, the division which is to implement ISO 27001 is using Company's HR procedures. Does the division need to describe exactly in SoA what processes are shared, or is it enough to write in SoA that HR Security controls are Shared with the Company?

Answer: By "processes" I'm assuming you are referring to security processes performed in a shared way by the Division and the Company's HR.

Considering that, first of all, for shared controls you have to state clearly in the SoA which part of each control is implemented by whom. Regarding the level of detail about how a control is implemented, if you have documents related to HR security available (e.g., policies or procedures) you can write a small text to provide an general overview and include references to these documents, or to the location where they can be found. If you do not have these documents available then you have to describe in SoA the whole HR security process.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 22, 2017

Nov 22, 2017

Suggested Topics

Guest user Created:   Sep 17, 2017 ISO 27001 & 22301
Replies: 2
0 1

SOA content fields

Guest user Created:   Feb 15, 2019 ISO 27001 & 22301
Replies: 1
0 0

SoA information

Guest user Created:   Dec 04, 2018 ISO 27001 & 22301
Replies: 1
0 0

Toolkit content