Загрузка...

What is an ISO 27001 RASCI Matrix? An accountability matrix? - ISO 27001 Clause 7.1 #iso27001

You can follow this method. You're listing out all of the controls and assigning individuals to be accountable for them. You also assign people to be responsible for completing the task.

Responsibility and Accountability
Remember that the actual work can be handled by an external third party. You can have someone inside your organisation who is accountable for a control, even if you outsource the work to an external group. This arrangement is perfectly acceptable and is covered within the standard guidelines.

The RACI Matrix
Depending on how you want to manage your operations, you'll also find a RACI matrix available to you. This is a slightly more sophisticated tool than the standard accountability matrix. You can easily search online for RACI tables to learn more about them. This explanation won't be a full tutorial on how to implement the RACI matrix.

What you'll see, though, is that the format is very similar to the accountability matrix. You still have entries for the management system and for the annex. However, you'll have more columns because you are now identifying people who are Consulted, Informed, and who Support the task.

Therefore, if the RACI matrix is what you prefer or need, you can simply convert your existing accountability matrix into the RACI format.

#iso27001certification

Видео What is an ISO 27001 RASCI Matrix? An accountability matrix? - ISO 27001 Clause 7.1 #iso27001 канала Stuart Barker
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять