July 2024
Intermediate to advanced
486 pages
11h 19m
English
A key theme of ISO 27001, and of the ISO 27002 controls, is that policies and procedures must be documented so that they can be understood, enforced, and improved. Clarity about operational procedures and responsibilities is an important contributor to the correct and secure use of information processing facilities.
Control 5.37 of ISO 27002 says the organization should document the operating procedures that were identified as necessary in the security policy and which are being discussed at length in this book. As discussed in Chapter 3 (management system integration), the document control principles of ISO 9000 are applicable to ISO 27001, and all the operating procedures that ...
Read now
Unlock full access