Expert Advice Community

Guest

Making the transition from 2005 to 2013 revision of ISO 27001

  Quote
Guest
Guest user Created:   May 17, 2016 Last commented:   May 17, 2016

Making the transition from 2005 to 2013 revision of ISO 27001

Say the company has ISO 27001 already and wants to update to 2013 version - is this done with the assessing body, and is there a seminar that covers this on your course ?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic May 17, 2016

Answer: I assume your company is already certified against 2005 revision of ISO 27001, and now you want to certify against 2013 revision - yes, this needs to be done with a certification body.

See also:
- article How to make a transition from ISO 27001 2005 revision to 2013 revision https://advisera.com/27001academy/knowledgebase/how-to-make-a-transition-from-iso-27001-2005-revision-to-2013-revision/
- webinar recording: What’s new in ISO 27001 2013 revision: How to make the transition from ISO 27001 2005 to 2013 revision https://advisera.com/27001academy/webinar/transition-iso-27001-2013-to-iso-27001-2022-free-webinar-on-demand/

What is the process of the reassessment with the assessing body, do they look at all the internal audit work during the assessment ?

Answer: Until now your 2005 certificate has expired because the transiti on period is over, so you have to go for the completely new certification against 2013 revision of ISO 27001. And yes, they will look at how you're done your internal audit, and they will check also all the other elements of your ISMS.

See also:
- article Which questions will the ISO 27001 certification auditor ask? https://advisera.com/27001academy/blog/2015/07/20/which-questions-will-the-iso-27001-certification-auditor-ask/
- article Becoming ISO 27001 certified – How to prepare for certification audit https://advisera.com/27001academy/iso-27001-certification/

If during the assessment there were some areas that needed addressing, then does the company get an opportunity to put a plan together to rectify and still maintain the certificate ?

Answer: Yes, if the certification body finds nonconformities, they will give you a deadline until which you'll have to resolve those problems.

See also:
- article Major vs. minor nonconformities in the certification audit https://advisera.com/27001academy/blog/2014/06/02/major-vs-minor-nonconformities-in-the-certification-audit/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 17, 2016

May 17, 2016

Suggested Topics