Maintaining ISMS Certifications from a merging company
This is a scenario.
Company A is currently ISMS certified – The scope: Security Operation Center (SOC); location at office A, using System A
Company A need to be re-certified by end of February.
Company B (not ISMS certified) bought over company A. Their merging exercise to be completed in March. They intend to relocate the SOC to location B, may be used new System B (later after the relocation). They want to maintain the ISMS certification of the SOC (previously company A). Appreciate your advise: What is their action plan in order to maintain the ISMS certification?
Company B also intend to extend the scope of ISMS – New Scope – Whole company? What they need to do? Thank you