Expert Advice Community

Guest

Updating existing information security policies

  Quote
Guest
Guest user Created:   Jan 13, 2016 Last commented:   Jan 13, 2016

Updating existing information security policies

I am trying to update and simplify 9 Info security policies to align better with ISO 27001. How do you advise I go about this. There may be some duplication with control groups. Should I follow your template?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
DejanK Jan 13, 2016

Answer:

ISO 27001 is not only about security policies, so this task can't be made just by improving your policies without doing the prior analysis. The whole logic of ISO 27001 is based on risk assessment, which means once you know where your risks are then you can start writing the documents and implement the controls that will mitigate those risks.

If you're not particularly satisfied with your existing documents, than it might be easier to write completely new documents - in such case our templates will certainly help you.

Here you'll find the details on this topic:

The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/
ISO 27001 implementation checklist https://advisera.com/27001academy/knowledgebase/iso-27001-implementation-checklist/
List of mandatory documents required by ISO 27001 (2013 revision) https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/
8 criteria to decide which ISO 27001 policies and procedures to write https://advisera.com/27001academy/blog/2014/07/28/8-criteria-to-decide-which-iso-27001-policies-and-procedures-to-write/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 13, 2016

Jan 13, 2016