Expert Advice Community

Guest

Certification coverage

  Quote
Guest
Guest user Created:   Apr 30, 2019 Last commented:   Apr 30, 2019

Certification coverage

To what extent will the certification be issued to a corporate entity? If it will be issued to corporate X, will it cover all of its entities subsidiaries and affiliates? Or, should every legal entity needs its own certification?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 30, 2019

Answer:

The certification coverage will depend on the ISMS scope definition. If it is issued to corporate X, then we need to verify which locations (i.e., addresses) where included. If the address of any subsidiary or affiliated entity is included, then it is covered by the certificate (of course this entity will have to go through all certification process together with the main Corporate X)

Adopting a single certificate for all units or separated ones for each unit is a business decision, depending on their objectives and strategies, but in general organizations like these adopt the model of one certification for each unit, because a change on an unit does not impact the certification of other units.

These articles will provide you further explanation about scope definition:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 30, 2019

Apr 30, 2019

Suggested Topics

Guest user Created:   Feb 20, 2019 ISO 27001 & 22301
Replies: 1
0 0

Certification coverage

Guest user Created:   May 01, 2019 ISO 27001 & 22301
Replies: 1
0 0

Certification process