Expert Advice Community

Guest

Toolkit content

  Quote
Guest
Guest user Created:   Mar 10, 2019 Last commented:   Mar 10, 2019

Toolkit content

I do have a couple of questions for you regarding the documentation in the toolkit. Hopefully you want to answer these questions.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 10, 2019

1. 'Security Procedures for IT Department'. XXXX is an IT company, this means there is no specific IT department. Is it still obligatory for us to make this document?

Answer: First it is important to understand that this document is intended to the "department" that runs the IT systems that support the organization's business. In your case this document would be intended to the area that runs your internal IT systems, but also could be applied to IT processes you run for your customers.

Second, this document is mandatory only if controls that ISO 27001 Annex covers are required by your business, considering that:
- There are risks identified as unacceptable in the risk assessment that require the implementation of controls covered by this document
- There are legal requirements (e.g., contracts, laws, and regulations) that require the implementation of the controls covered by this document
- There is a top management decision requiring the implementation of the controls covered by this document

If none of these options occur for the controls related to this document there is no need to implement this document.

This article will provide you further explanation about selecting controls:
- The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

2. Risk Treatment Table: Regarding the zero's at the last column (which is Risk), are these put as an example?
Answer: The zero is the result of the formula used to calculate risk (consequence plus likelihood, on columns L and M respectively), and on the template the zero is because the template is empty. Included in the toolkit you have access to a video tutorial that will guide you on filling the Risk Treatment Table with real data.

3. Statement of Applicability: Aren't we supposed to tick the controls which are mandatory for ISO 27001 (the ones affiliated with the documentation in your PDF, ex. Statement of Acceptance of ISMS Documents is mandatory, so A.7.1.2 is applicable) ?

Answer: The Statement of Applicability goes beyond ticking applicable controls, because you also have to document the justification to apply, or not to apply, a control from Annex A, and the implementation status of each control. Additionally, considering your example, in fact it is the other way around (i.e., because A.7.1.2 is applicable the Statement of Acceptance of ISMS Documents is mandatory).

This article can provide you further information about SoA:
- The importance of Statement of Applicability for ISO 27001 https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/

4. Validity and document management (which is at the bottom of nearly each document): required or not? If it is required, may we present it on a different way (ex. in a table) ?
Answer: Validity helps fulfill requirements regarding clause 7.5.2 Creating and updating documented information, while document management helps to identify and control records related to the document, fulfilling clause 7.5.3 Control of documented information. Since ISO 27001 does not prescribe how to present this information, you can use any presentation that you see best for your organization.

These materials can provide you further information about document management:
- Document management in ISO 27001 & BS 25999-2 https://advisera.com/27001academy/blog/2021/06/27/how-to-manage-documents-according-to-iso-27001-and-iso-22301/
- Managing ISO Documentation: A Plain English Guide https://advisera.com/books/managing-iso-documentation-plain-english-guide/

5. Confidentiality Statement. Is the Policy for Handling Classified Information the same Policy as the Information Classification Policy? I could not find this in the toolkit.

Answer: These are the old and new name for the same policy, which covers both the information classification process and the handling of classified information.

This article will provide you further explanation about information classification:
- Information classification according to ISO 27001 https://advisera.com/27001academy/blog/2014/05/12/information-classification-according-to-iso-27001/
Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 10, 2019

Mar 10, 2019

Suggested Topics

Guest user Created:   Sep 11, 2021 ISO 27001 & 22301
Replies: 1
0 0

Toolkit content

Guest user Created:   May 28, 2021 ISO 27001 & 22301
Replies: 1
0 0

Toolkit content

Guest user Created:   Mar 11, 2021 ISO 27001 & 22301
Replies: 1
0 0

Toolkit content