Expert Advice Community

Guest

ISAE 3402 and ISO 27001

  Quote
Guest
Guest user Created:   Feb 27, 2018 Last commented:   Feb 28, 2018

ISAE 3402 and ISO 27001

This is what I'm meet with in Denmark when I talk to some accountants about ISO 27001.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 27, 2018

In Danish: "Revisionsstandard ISAE 3402 type II med udgangspunkt i ISO 27002 kontrolbeskrivelsen"
Trying to translate this to English it would be something like: "The accounting standard ISAE 3402 type II, using the ISO 27002 control description"
They tell me this is an alternative to ISO 27001 certification.
If You know anything about it, can You help me understand?

Answer: ISO 27001 has a more comprehensive approach. It requires you to identify and evaluate all requirements that can impact your organization in terms of information security, while ISAE 3402 focus on documenting that an organization has adequate internal controls, generally approached from a financial perspective. So you can only consider ISAE 3402 type II as an alternative for ISO 27001 if you do not have any other legal requirements to fulfil regarding information security, or you are not obliged to comply with ISO 27001. Since these conditions are extremely rare to happen (organiza tions generally have multiples legal requirements regarding protection of information), it is better to consider ISO 27001 certification.

Additionally, ISO 27001 certification is much more widespread and therefore much better recognized than ISAE 3402.

Quote
0 0
Guest
egeskov Feb 28, 2018

Thanks for the answer :-)
I'm also confused about the mentioning of ISO 27002. What is that?

Quote
0 0
Expert
Rhand Leal Mar 01, 2018

ISO 27002 is a supporting standard that provides guidance and recommendations for the implementation of ISO 27001 Annex A controls.

This article will provide you further explanation about ISO 27002:
- ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 27, 2018

Mar 01, 2018

Suggested Topics