The Elsmar Cove Wiki More Free Files The Elsmar Cove Forums Discussion Thread Index Post Attachments Listing Failure Modes Services and Solutions to Problems Elsmar cove Forums Main Page Elsmar Cove Home Page

Go Back   The Elsmar Cove Forum > ISO (International Organization for Standardization) Standards > ISO/IEC 27000 - Information Security Management Systems (ISMS)
Forum Username


Elsmar Cove Forum Sidebar
Custom Search
Monitor the Elsmar Forum
Monitor New Forum Posts
Follow Marc & Elsmar
Elsmar Cove Forum RSS Feed  Marc Smith's Google+ Page  Marc Smith's Linked In Page   Marc Smith's Elsmar Cove YouTube Page  Marc Smith's Facebook Page
Elsmar Cove Groups
Elsmar Cove Google+ Group  Elsmar Cove LinkedIn Group  Elsmar Cove Facebook Group
Sponsor Links







Donate and $ Contributor Forum Access
Sponsored Links
Courtesy Quick Links

Links that Elsmar Cove visitors will find useful in your quest for knowledge:


Howard's
International Quality Services

Atul's
Symphony Technologies

Marcelo Antunes'
SQR Consulting

Bob Doering's
Correct SPC - Precision Machining


NIST's Engineering Statistics Handbook

IRCA - International Register of Certified Auditors

SAE - Society of Automotive Engineers

Quality Digest Portal

IEST - Institute of Environmental Sciences and Technology

ASQ - American Society for Quality


Related Topic Tags
isms (information security management system), policy documents, procedure approval, procedures (general)
Reply
 
Thread Tools Search this Thread Rate Thread Content Display Modes
  #1  
Old 31st July 2012, 04:18 AM
baynoli baynoli is offline
Involved in Discussions

 
Registration Date: Feb 2008
 
Posts: 24
Thanks Given to Others: 0
Thanked 0 Times in 0 Posts
Karma Power: 24
Karma: 10
baynoli has less than 100 Karma points so far.
Please Help! Is policy required for each procedure in ISMS ?

Hi All,

Good Day,

In documentation part of isms, do i really need a policy/ies for each procedure I made?

Cheers Everyone,

Thanks,

klooden

Sponsored Links
  #2  
Old 31st July 2012, 04:46 AM
Stijloor's Avatar
Stijloor Stijloor is offline
Cross Forum Moderator

 
Registration Date: May 2003
Location: Charlotte, North Carolina.
 
Posts: 13,437
Thanks Given to Others: 2,950
Thanked 4,274 Times in 3,029 Posts
Karma Power: 1431
Karma: 23917
Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.
Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.Stijloor is appreciated, and has over 1700 Karma points.
Re: Policies and Procedures

A Quick Bump!

Can someone help?

Thank you very much!!
Sponsored Links

  #3  
Old 31st July 2012, 05:23 AM
Colin's Avatar
Colin Colin is offline
Appreciated Information Resource

 
Registration Date: Oct 2006
Location: UK - North West
 
Posts: 1,293
Thanks Given to Others: 340
Thanked 861 Times in 524 Posts
Karma Power: 169
Karma: 6686
Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.
Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.Colin is appreciated, and has over 1700 Karma points.
Re: Policies and Procedures

I am not quite sure I understand the question. 27001 requires an ISMS policy (4.2.1 b) and it requires procedures in various areas e.g. for monitoring and reviewing the ISMS.

I don't see the need for a policy for each procedure though it would be normal to define the purpose and scope of each procedure you prepare.
__________________
If you think training is expensive, try ignorance
Thank You to Colin for your informative Post and/or Attachment!
  #4  
Old 11th August 2012, 12:27 AM
Richard Regalado Richard Regalado is offline
Appreciated Member

 
Registration Date: Mar 2005
Location: Philippines
Age: 40
 
Posts: 180
Thanks Given to Others: 7
Thanked 105 Times in 69 Posts
Karma Power: 55
Karma: 1575
Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.Richard Regalado is appreciated, and has over 1500 Karma points.
Send a message via Yahoo to Richard Regalado
Re: Is policy required for each procedure in ISMS ?

Colin is correct. You need an information security policy. But not a policy for all of your procedures.

If you are referring to the Annex-A controls, I usually create "sub-policies" for each applicable control and have them in an ISMS manual. BTW, an ISMS manual is not a requirement but I found it very useful to link to other documented information within the ISMS.

For example for Control A.10.4.1 Controls against malicious code, you could have a policy statement which says "All information processing facilities which connect to the organization's network and processes information owned by the organization shall have the official anti-virus software used by the organization and is updated frequently."
Thank You to Richard Regalado for your informative Post and/or Attachment!
Reply

Lower Navigation Bar
Go Back   The Elsmar Cove Forum > ISO (International Organization for Standardization) Standards > ISO/IEC 27000 - Information Security Management Systems (ISMS)

Do you find this discussion thread helpful and informational?


Bookmarks


Visitors Currently Viewing this Thread: 1 (0 Registered Visitors (Members) and 1 Unregistered Guest Visitors)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Forum Search
Display Modes Rate Thread Content
Rate Thread Content:

Forum Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Discussion Threads
Discussion Thread Title Thread Starter Forum Replies Last Post or Poll Vote
ISMS (Information Security Management System) Policy vs. Information Security Policy AnandR ISO/IEC 27000 - Information Security Management Systems (ISMS) 1 29th May 2012 05:18 AM
ISMS Firewall security policy sample template needed. ameerjani007 ISO/IEC 27000 - Information Security Management Systems (ISMS) 2 6th July 2010 09:39 AM
ISO 27001:2005 ISMS implementation process & Procedure ameerjani007 ISO/IEC 27000 - Information Security Management Systems (ISMS) 2 20th June 2010 08:23 AM
Signature Required on Quality Policy? amanbhai ISO 17025 and related Metrology Topics - Measurement Devices, Calibration and Test Laboratories 28 1st November 2007 02:27 PM
Policy vs. Procedure - Vocabulary / Terminology - Definition of Policy vs. Procedure Telefonia Definitions, Acronyms, Abbreviations and Interpretations 5 6th December 2001 10:12 AM



The time now is 01:27 PM. All times are GMT -4.
Your time zone can be changed in your UserCP --> Options.


   


Marc Timothy Smith - Elsmar.com
8466 LeSourdsville-West Chester Road, Olde West Chester, Ohio 45069-1929
513 341-6272