Hi,
I just have a few controls I need to sort for the Statement Of Applicability. One being this policy. We are only a small company of 13 and don't have the resource to have an independent person audit the ISO internally. We audit controls monthly , is this satisfactory to put in this policy? or should I just not do a policy and add to the SOA the reasons why we don't?
Thanks
I just have a few controls I need to sort for the Statement Of Applicability. One being this policy. We are only a small company of 13 and don't have the resource to have an independent person audit the ISO internally. We audit controls monthly , is this satisfactory to put in this policy? or should I just not do a policy and add to the SOA the reasons why we don't?
Thanks