SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

27001 query

  Quote
Guest
Guest user Created:   Jan 20, 2023 Last commented:   Jan 20, 2023

27001 query

Hi Dejan

*** is progressing with its Electronic Money Institution (EMI) licence with the Central Bank of YYYY. 

Below is a query received from the Institution: 

13.1(h) A detailed risk assessment in relation to its payment services, including fraud: 
a. Please provide verification of the progress of the gap analysis the firm is undertaking against ISO 27001.

Would you be able to advise if we conduct a risk assessment specifically of payment services to ID the gaps this may suffice for the Institution? Or is there another process we could do? 

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jan 20, 2023

From the provided requirement, a risk assessment covering specifically the payment services is enough to fulfill it. Depending upon where this process is performed, you may also consider risks related to supplier management (e.g., the payment process is performed using a cloud service provider).

For further information, see:

Quote
0 1

Comment as guest or Sign in

HTML tags are not allowed

Jan 20, 2023

Jan 20, 2023

Suggested Topics

Guest user Created:   Mar 01, 2023 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 query

Guest user Created:   Jan 13, 2022 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 query

Guest user Created:   Jun 14, 2021 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 query