Expert Advice Community

Guest

Training and awareness statements in the Information security policy

  Quote
Guest
Guest user Created:   Apr 26, 2016 Last commented:   Apr 26, 2016

Training and awareness statements in the Information security policy

In your information security policy template what do these two statements mean and how are they different?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Apr 26, 2016

* [job title] is responsible for adopting and implementing the Training and Awareness Plan, which applies to all persons who have a role in information security management
* job title] will implement information security training and awareness programs for employees

Answer:

The first statement defines who is responsible for approving the Training and Awareness Plan, typically this would be CEO in smaller companies; the second statement defines who is responsible for the execution of this plan - in smaller companies this would usually be a person responsible for information security.

By the way, the Training and Awareness Plan is also included in the ISO 27001 toolkit.

This article might also help you: How to perform training & awareness for ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/05/19/how-to-perform-training-awareness-for-iso-27001-and-iso-22301/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 25, 2016

Apr 25, 2016

Suggested Topics