Security Policy: Difference between revisions
Jump to navigation
Jump to search
| Line 120: | Line 120: | ||
:2. Determine all controls that are necessary to implement the information security risk treatment option(s) chosen; | :2. Determine all controls that are necessary to implement the information security risk treatment option(s) chosen; | ||
<small>NOTE Organizations can design controls as required, or identify them from any source. </small> | <small>NOTE Organizations can design controls as required, or identify them from any source. </small> | ||
:3. Compare the controls determined above with those in Annex A of ISO/IEC 27001:2013 and verify that no necessary controls have been omitted; | :3. Compare the controls determined in [[Security_Policy#Information_security_risk_treatment|3.1.3]].2 above with those in Annex A of [https://drive.google.com/file/d/0B98VxoZqj8C6R0Jva0pSWTFyQzA/view ISO/IEC 27001:2013] and verify that no necessary controls have been omitted; | ||
<small>NOTE 1 Annex A contains a comprehensive list of control objectives and controls. Users of this International Standard are directed to Annex A to ensure that no necessary controls are overlooked. | <small>NOTE 1 Annex A contains a comprehensive list of control objectives and controls. Users of this International Standard are directed to Annex A to ensure that no necessary controls are overlooked. | ||