SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

SoA’s justification for the selection of control

  Quote
Guest
Guest user Created:   Jun 01, 2020 Last commented:   Jun 01, 2020

SoA’s justification for the selection of control

I have two questions, first about SoA’s justification for the selection of control and second about secure areas:

1. If there is no risks from the risk treatment (thus nor risk treatment number for the control), should one use risks from the risk assessment (select risk numbers which have already treated by a control) for the justification for selection?

2. I have a hard time to figure out which are differences between secure areas (A.11.1.5) and securing offices, rooms and facilities?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jun 01, 2020

1. If there is no risks from the risk treatment (thus nor risk treatment number for the control), should one use risks from the risk assessment (select risk numbers which have already treated by a control) for the justification for selection?

our assumption is correct. If you identified during the risk assessment that relevant risks are already in acceptable levels because the related control is already implemented, then you can use these risks as justification for the applicability of the control in the SoA.

For further information, see:

2. I have a hard time to figure out which are differences between secure areas (A.11.1.5) and securing offices, rooms and facilities?

Control A.11.1.5 refers to how to work on secure areas (e.g., do not use cameras inside, forbid unsupervised work, etc.), while control A.11.1.3 refers to physical controls implemented to improve the security of the environment (e.g., located away from public traffic, soundproof, etc.).

These articles will provide you a further explanation about physical security:

These materials will also help you regarding ISO 27001 controls:

Quote
0 1

Comment as guest or Sign in

HTML tags are not allowed

Jun 01, 2020

Jun 01, 2020