Security Policy: Difference between revisions

Jump to navigation Jump to search
Line 117: Line 117:
The organization shall define and apply an information security risk treatment process to:
The organization shall define and apply an information security risk treatment process to:


# Select appropriate information security risk treatment options, taking account of the risk assessment results;
:1. Select appropriate information security risk treatment options, taking account of the risk assessment results;
# Determine all controls that are necessary to implement the information security risk treatment option(s) chosen;
:2. Determine all controls that are necessary to implement the information security risk treatment option(s) chosen;
     <small>NOTE Organizations can design controls as required, or identify them from any source. </small>
     <small>NOTE Organizations can design controls as required, or identify them from any source. </small>
# Compare the controls determined above with those in Annex A of ISO/IEC 27001:2013 and verify that no necessary controls have been omitted;
:3. Compare the controls determined above with those in Annex A of ISO/IEC 27001:2013 and verify that no necessary controls have been omitted;


   <small>NOTE 1 Annex A contains a comprehensive list of control objectives and controls. Users of this International Standard are directed to Annex A to ensure that no necessary controls are overlooked.
   <small>NOTE 1 Annex A contains a comprehensive list of control objectives and controls. Users of this International Standard are directed to Annex A to ensure that no necessary controls are overlooked.
Line 126: Line 126:
   NOTE 2 Control objectives are implicitly included in the controls chosen. The control objectives and controls listed in Annex A are not exhaustive and additional control objectives and controls may be needed.</small>
   NOTE 2 Control objectives are implicitly included in the controls chosen. The control objectives and controls listed in Annex A are not exhaustive and additional control objectives and controls may be needed.</small>


# Produce a Statement of Applicability that contains the necessary controls above and justification for inclusions, whether they are implemented or not, and the justification for exclusions of controls from Annex A;
:5. Produce a Statement of Applicability that contains the necessary controls above and justification for inclusions, whether they are implemented or not, and the justification for exclusions of controls from Annex A;


# Formulate an information security risk treatment plan; and
:6. Formulate an information security risk treatment plan; and


# Obtain risk owners’ approval of the information security risk treatment plan and acceptance of the residual information security risks.
:7. Obtain risk owners’ approval of the information security risk treatment plan and acceptance of the residual information security risks.


The organization shall retain documented information about the information security risk treatment process.
The organization shall retain documented information about the information security risk treatment process.