SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

IT Managed Service Providers

  Quote
Guest
Guest user Created:   Mar 02, 2021 Last commented:   Mar 02, 2021

IT Managed Service Providers

1. Is there an ISO certification we should look at?

2. What would be involved to get certified and what sort of costs would we expect?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 02, 2021

1. Is there an ISO certification we should look at?

Please note that ISO certifications are not mandatory by themselves, although some countries have established laws and regulations that are easier to be fulfilled by adopting them, and an increased number of customers are preferring ISO-certified organizations as suppliers because they consider such organizations are more capable to help them.

Considering that, you need to evaluate your legal environment and customers’ profile to see if an ISO certification is interesting to you.

Broadly speaking, IT Managed Service Providers, should consider the following certifications:

  • ISO 20000: related to the management of IT services
  • ISO 27001: related to the management of information security
  • ISO 9001: related to quality management

These standards share many common requirements, so you can implement them in an integrated way.

These articles will provide you a further explanation about ISO standards:

This article can provide you a customer point of view (the same general concept applies to all ISO management standards):

2. What would be involved to get certified and what sort of costs would we expect?

After the implementation of documents and controls required by the specific standard, you need to make sure that everyone in the company is complying with documents, i.e., performing all the activities prescribed there. After that, you can work on selecting your certification body.

Our toolkit can help you with the implementation: 

These articles will provide you a further explanation about the ISO 27001 implementation process:

Regarding costs, without detailed information about the certification scope it is not possible to give you a precise answer, but broadly speaking, what I can tell you is that these are some cost issues you should consider:

  • Training and literature
  • External assistance
  • Technologies to be updated/implemented
  • Employee's effort and time
  • The certification process

These materials can provide you more information:

For the duration of the implementation:

These materials will also help you regarding ISO 27001 project:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 02, 2021

Mar 02, 2021

Suggested Topics