| Name | Control area / control title / control description | Applied? | Justification for inclusion* | Justification for exclusion | Doc |
|---|---|---|---|---|---|
| A.5 | Organisational Controls ▼ | ||||
| A.5.1 | Policies for information security
▼
Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur. |
ISMS-C DOC 5.1-8 | |||
| Do you have a written information security policy? | |||||
| Do you have written topic-specific policies (such as an access control or backup policy) to support your information security policy where necessary? | |||||
| Are your information security and topic-specific policies approved by management? | |||||
| Are those policies published, communicated to and acknowledged by relevant personnel and interested parties? | |||||
| Are those policies reviewed at planned intervals and after significant changes occur? | |||||
| A.5.2 | Information security roles and responsibilities
▼
Information security roles and responsibilities shall be defined and allocated according to the organization needs. |
ISMS-C DOC 5.1-8 | |||
| Have you defined information security roles and responsibilities? | |||||
| Have you allocated information security roles and responsibilities according to organisation needs? | |||||