Which controls are related to the Annex A controls of ISO/IEC 27001 and are often selected from other guides and standards or defined by the organization to meet its specific needs?
ISO/IEC 27001 Annex A provides a comprehensive list of information security controls. However, it's not a prescriptive "must-do" list. Organizations are required to conduct a risk assessment and then select the controls from Annex A (and potentially other sources) that are relevant to their specific risks and operational environment.
"Specific controls" refers to these chosen controls that are tailored to the organization's unique needs, often drawing from various sources beyond just Annex A, or even defining new controls as necessary.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Cyza
1 week agoROCTW
4 weeks agohussain_rj2
5 months ago