I have experience of ISMS auditing only and now I have taken the responsibility of ISMS implementation.
My Organization (X) is providing a new software solution to another Org. (Y). It will be implemented in two phases to replace their similar old systems. As a part of deliverable, we have to get it certified also with ISO 27001 standard for both phase-1 and phase-2 systems.
Phase-1 commissioning of new system is completed in the Aug 2018, and Phase-2 will be completed by March 2019.
Note: Phase-1 system and Phase-2 systems are similar.
Query:
My query is about when to start the ISMS implementation?
I am planning to start the ISMS implementation for Phase-1 from Sep 2018 (next month) itself. Later when Phase-2 will be completed in Mar 2019, I will start ISMS implementing in April 2019 for phase-2 and will integrate the same with phase-1. As per the ISO27K requirement, I will keep it operational for at least 3 months after implementation and then will go for external audit for certification. Need your advice if t he above planning is fine.
Answer:
First it is important to understand that ISO 27001 does not certify software solutions. ISO 27001 certification aims for information, processes, and/or locations, not products or services.
Considering that, you can't certify this software solution as part of your commissioning. Any ISO 27001 certification involving this software solution (e.g., certifying the process where this solution is used) should be an initiative of Organization Y, to be handled as a separated project.
Comment as guest or Sign in
Aug 15, 2018