ISO 27001 and 27701 Controls - Tips and Tricks
Updates to controls that are needed for ISO 27001/27701
Written By Micah
When using Strike Graph to manage your controls and adding on the ISO 27001 and/or 27701 frameworks, we recommend making a few updates to the control language to cover additional requirements. You can use the guidance below to make these changes to the controls within your Control Library and to activate additional controls that may be relevant to your organization.
Remember, you can and should edit the control descriptions to ensure that they accurately describe your processes.
Business Continuity
In some organizations, the Business Continuity Plan will include a section on Disaster Recovery. Add the following to the existing control description: The organization has considered strategies for information and communication technology services as an element of its Business Continuity Plan.
Information Security Roles
Add the following to the existing control description: The responsibilities for ensuring that the information security management system conforms to ISO 27001 and reporting on the performance of the ISMS to top management, is available to the organization.
Non-Disclosure Agreement
Add the following to the control description: The NDA is regularly reviewed.
Operational Planning
This includes the first version of the Risk Assessment, Risk Treatment, and Risk Treatment Plan; the controls from Annex A stated as applicable in the Statement of Applicability; and the documents related to clauses 4 to 10.
Operating Procedure
Procedures should include:
configuration of systems
processing and handling of information
jobs scheduled
backups
recovery
monitoring of systems
handling errors and deviations
media handling
Risk Assessment Methodology
Ensure that privacy risks are considered. Strike Graph provides a recommended template.
Security Training
Include the following in the control description:
The training includes the Information Security Policy, how staff contribute to the effectiveness of the information security management system, the benefits of improved information security performance, and the implications of not conforming with the information security management system requirements.