Expert Advice Community

Guest

Which clauses must be covered with particular documents?

  Quote
Guest
Guest user Created:   Dec 19, 2016 Last commented:   Dec 19, 2016

Which clauses must be covered with particular documents?

I’ve purchased the premium kit for ISO 27001 and noticed that the templates have references to relevant ISO 27001:2013 clauses. In many cases, the list of relevant clauses in each template is far more than what is listed here https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/ For example, at the URL above, only clasue A.8.1.3 is listed. However, in the Acceptable Use Policy template found in the premium documentation kit, you’ve listed these references: ISO/IEC 27001 standard, clauses A.6.2.1, A.6.2.2, A.8.1.2, A.8.1.3, A.8.1.4, A.9.3.1, A.11.2.5, A.11.2.6, A.11.2.8, A.11.2.9, A.12.2.1, A.12.3.1, A.12.5.1, A.12.6.2, A.13.2.3, A.18.1.2.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Dec 19, 2016

What is needed for ISO 27001 certification?

Answer:

The article you are referencing to lists the minimum of the documents you need to have. However, in most cases you will need to implement some other documents as well, because this will be required by the situation in your company - here's the article that will help you with such decisions : 8 criteria to decide which ISO 27001 policies and procedures to write https://advisera.com/27001academy/blog/2014/07/28/8-criteria-to-decide-which-iso-27001-policies-and-procedures-to-write/

We have written our policies and procedures in such a way that makes it easy for you to delete any part of them - when you read this template for Acceptable Use Policy, you will find comments saying e.g. "Delete this section if you marked control xyz as inapplicable" - this means you have to assess if a particular control is needed for you, and if not you can simply delete a part of the document that describes it.

This article will help you with understanding the logic of when you can mark a control as applicable or not: The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

This article you might also find useful: How to structure the documents for ISO 27001 Annex A controls https://advisera.com/27001academy/blog/2014/11/03/how-to-structure-the-documents-for-iso-27001-annex-a-controls/

These materials will also help you regarding selection of controls and documenting them:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your
Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course
https://advisera.com/training/iso-27001-foundations-course/
- Conformio (online ISO 27001 tool) https://advisera.com/conformio/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 19, 2016

Dec 19, 2016