SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

How to treat suppliers that are ISO 27001 certified

  Quote
Guest
Guest user Created:   Aug 04, 2016 Last commented:   Aug 04, 2016

How to treat suppliers that are ISO 27001 certified

We have a data centre who manages our data and they host our Office 365. The office we rent is in a shared building, they provide us with a channel which links us with our Data Centre. They are both ISO 27001 certified - do I class them as suppliers in our ISO 27001? If I do what information do I need from them, what documents do I need to produce and do I need to audit them?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Aug 04, 2016

Answer: The fact that they are ISO 27001 certified doesn't change their status towards you - so yes, you have to treat them as suppliers. To understand the details on how to handle suppliers, please read this article: 6-step process for handling supplier security according to ISO 27001 https://advisera.com/27001academy/blog/2014/06/30/6-step-process-for-handling-supplier-security-according-to-iso-27001/

My second question is that as we are a new and small company we do not have any IT department so we (personally) managed our IT equipment, will this cause us problems in our certification?

Answer: No, your size and the fact that you are managing your IT equ ipment won't cause any problems at the certification, as long as you comply with your policies and procedures.

Is it better to have a dedicated IT department or have someone who manages our IT?

Answer: I'm not sure if I understood your question correctly - if you meant whether it is better to have your own IT department or to outsource the IT function, this is primarily a business issue (what is more profitable) and a skill issue (does your IT equipment require some special skills that might not be easy to find in the market).

Or can we just put encryption / passwords / administration rights to particular systems to get round this??

Answer: Managing security is not only about encryption, passwords and administration rights - the best thing for you would be to go through this free online training to learn all that is important for security management: ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 03, 2016

Aug 03, 2016

Suggested Topics

Guest user Created:   Jun 30, 2021 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 questions

Guest user Created:   Apr 17, 2019 ISO 27001 & 22301
Replies: 3
0 0

Assets of IaaS