Expert Advice Community

Guest

Toolkit list of documents

  Quote
Guest
Guest user Created:   Jul 30, 2017 Last commented:   Jul 30, 2017

Toolkit list of documents

1- I have two documents, both of which include a checklist of Mandatory Documents required by ISO 27001. However, there are some minor differences. Could you please confirm that the revised 2015 version 3.1 is the newest update and I should disregard the 2013 revision.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 30, 2017

Answer: Yes, the latest revision of the ISO 27001 & ISO 22301 Premium Documentation Toolkit is the 3.1, published in 2015

By the name of the documents you provided, it seems to me you are comparing the white paper "Checklist of mandatory documentation required by ISO 27001:2013", available as free download at https://info.advisera.com/27001academy/free-download/checklist-of-mandatory-documentation-required-by-iso-27001, against the List of Documents file from the toolkit you bought, and you shouldn't do that. You should follow the information in the list of documents file in your toolkit.

2- Also, the Business continuity procedures is not required or used in the new version; however, it is required in the 2013 version.

Answer: This toolkit is fully compliant with ISO 2700 1:2013 and ISO 22301:2012. The requirement for businesses continuity procedures is covered with the Disaster Recovery Plan in the ISO 27001 Documentation Toolkit.

3 - Is the Supplier security policy no longer mandatory?

Answer: Supplier security policy is mandatory only if the results of risk assessments identify that there are unacceptable risks that can be treated by this control, there are legal or contractual requirements that demand the control to be applied, or if the organization has a recorded decision to apply this control. Besides these reasons, an organization is not obligated to implement a supplier security policy.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 30, 2017

Jul 30, 2017