What does 'Managing records kept on the basis of this document' mean?
Assign topic to the user
Answer:
The activities that are prescribed by policies and procedures almost always produce some kind of records - e.g. if you define the rule that you will perform the backup every 24 hours, you will have backup logs that are created every time the backup process is initiated.
Similar with BYOD policy - for example, section 3.2 requires you to create a list of persons who are allowed to use their own devices, and this particular list is then a record that needs to exist.
In all our templates you have a suggestion on what should be included in the section 4, i.e. what kind of records need to be produced.
See also this article: Records management in ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2014/11/24/records-management-in-iso-27001-and-iso-22301/
Comment as guest or Sign in
Jun 01, 2016