ISAE 3402 and ISO 27001
Assign topic to the user
In Danish: "Revisionsstandard ISAE 3402 type II med udgangspunkt i ISO 27002 kontrolbeskrivelsen"
Trying to translate this to English it would be something like: "The accounting standard ISAE 3402 type II, using the ISO 27002 control description"
They tell me this is an alternative to ISO 27001 certification.
If You know anything about it, can You help me understand?
Answer: ISO 27001 has a more comprehensive approach. It requires you to identify and evaluate all requirements that can impact your organization in terms of information security, while ISAE 3402 focus on documenting that an organization has adequate internal controls, generally approached from a financial perspective. So you can only consider ISAE 3402 type II as an alternative for ISO 27001 if you do not have any other legal requirements to fulfil regarding information security, or you are not obliged to comply with ISO 27001. Since these conditions are extremely rare to happen (organiza tions generally have multiples legal requirements regarding protection of information), it is better to consider ISO 27001 certification.
Additionally, ISO 27001 certification is much more widespread and therefore much better recognized than ISAE 3402.
Thanks for the answer :-)
I'm also confused about the mentioning of ISO 27002. What is that?
ISO 27002 is a supporting standard that provides guidance and recommendations for the implementation of ISO 27001 Annex A controls.
This article will provide you further explanation about ISO 27002:
- ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/
Comment as guest or Sign in
Mar 01, 2018