SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Statement of Applicability content

  Quote
Guest
Guest user Created:   Nov 15, 2018 Last commented:   Nov 15, 2018

Statement of Applicability content

Hi, the statement of applicability template contains all type of controls for all areas? Please I'm looking for controls on Wan Traffic Flow, Network Segregation, Pacht Mgmt process.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 15, 2018

Answer:

Advisera's Statement of Applicability template covers all controls defined in the ISO 27001 Annex A standard. These controls cover administrative, technical and physical areas in a general manner, but this list is not definitive or absolute, so you are free to add any controls you feel are needed.

The following controls are related to to the practices you mentioned:
- A.13.1.1 Network controls can cover Wan Traffic Flow
- A.13.1.3 Segregation in networks can cover Network Segregation
- A.14.2.4 Restrictions on changes to software packages, A.12.5.1 Installation of software on operational systems, and A.12.6.1 Management of technical vulnerabilities can cover Pacht Mgmt process

These articles will provide you further explanation about controls related to the mentioned practices:
- How to manage network security according to ISO 27001 A.13.1 https:/ /advisera.com/27001academy/blog/2016/06/27/how-to-manage-network-security-according-to-iso-27001-a-13-1/
- Requirements to implement network segregation according to ISO 27001 control A.13.1.3 https://advisera.com/27001academy/blog/2015/11/02/requirements-to-implement-network-segregation-according-to-iso-27001-control-a-13-1-3/
- How to manage technical vulnerabilities according to ISO 27001 control A.12.6.1 https://advisera.com/27001academy/blog/2015/10/12/how-to-manage-technical-vulnerabilities-according-to-iso-27001-control-a-12-6-1/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 15, 2018

Nov 15, 2018

Suggested Topics