Question about ISO-27001
Assign topic to the user
1 - Would it be acceptable to rent a bare office where no actual work happens? Wouldn't that mean that risks at the office location are being minimized or eliminated altogether and that the security control A.11 (physical and environmental security) becomes non-applicable?
If no actual work happens in this office, it wouldn’t make sense for the auditor, so probably this alternative wouldn’t be acceptable. The address should be related to a local where any activity related to the ISMS scope happens, or where the management responsible for the scope works.
2 - How does that compare to a rented room or desk in a co-working space?
I understand that the answer may depend on the CB and/or the kind of business being audited, but some generic advice would already be helpful for us to know our options on this matte
The same applies. If some business or management activity takes place in the local it may be used as the address for the certification scope, but this shared scenario is more complex to protect than the rented office.
Additionally, please note that the space needs to be rented for the duration of the certification. If you change the location, this will need to be notified to the certification body, and if no activity is performed there, this may represent resources are not properly allocated.
Comment as guest or Sign in
Jul 04, 2022