ISO 27001 Common Mistakes

January 31st, 2008 Jasjit Posted in All Posts, Information Security No Comments »

David Watson, one of the earliest exponents of the ISO 27001 standard and one of the most well known industry figures highlights some of the most common errors and mistakes in Information Security Management Systems, he has encountered over recent years:

  1. There is frequently a lack of traceability of the controls in the Statement of Applicability (SoA) to the Risk Assessment and Treatment Process (and back to the SoA);

  2. Risk Assessments often just look at technical risks and forget that the organization is a business with business risks;

    Read more »