Security Policy: Difference between revisions
Jump to navigation
Jump to search
| Line 117: | Line 117: | ||
The organization shall define and apply an information security risk treatment process to: | The organization shall define and apply an information security risk treatment process to: | ||
:1. Select appropriate information security risk treatment options, taking account of the risk assessment results; | |||
:2. Determine all controls that are necessary to implement the information security risk treatment option(s) chosen; | |||
<small>NOTE Organizations can design controls as required, or identify them from any source. </small> | <small>NOTE Organizations can design controls as required, or identify them from any source. </small> | ||
:3. Compare the controls determined above with those in Annex A of ISO/IEC 27001:2013 and verify that no necessary controls have been omitted; | |||
<small>NOTE 1 Annex A contains a comprehensive list of control objectives and controls. Users of this International Standard are directed to Annex A to ensure that no necessary controls are overlooked. | <small>NOTE 1 Annex A contains a comprehensive list of control objectives and controls. Users of this International Standard are directed to Annex A to ensure that no necessary controls are overlooked. | ||
| Line 126: | Line 126: | ||
NOTE 2 Control objectives are implicitly included in the controls chosen. The control objectives and controls listed in Annex A are not exhaustive and additional control objectives and controls may be needed.</small> | NOTE 2 Control objectives are implicitly included in the controls chosen. The control objectives and controls listed in Annex A are not exhaustive and additional control objectives and controls may be needed.</small> | ||
:5. Produce a Statement of Applicability that contains the necessary controls above and justification for inclusions, whether they are implemented or not, and the justification for exclusions of controls from Annex A; | |||
:6. Formulate an information security risk treatment plan; and | |||
:7. Obtain risk owners’ approval of the information security risk treatment plan and acceptance of the residual information security risks. | |||
The organization shall retain documented information about the information security risk treatment process. | The organization shall retain documented information about the information security risk treatment process. | ||