SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

SaaS products

  Quote
Guest
Guest user Created:   Jan 29, 2020 Last commented:   Jan 29, 2020

SaaS products

I was wondering if you had previous comments on scoping ISO 27001 for SaaS products.

Say a company is in the business of providing SaaA cloud-based solutions, with developers in house utilizing cloud infrastructure, what would be SO 27001 certification look like? The processes/ Datacenter used for the development of the SaaS application is ISO 27001 certified? the product might have multiple releases.. so stay away from calling out product as scope? and focus on people, process, site and dev, test, prod environments as scope?
And if the products are from multiple locations?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Jan 29, 2020

Basically, you need to include in the ISMS scope the cloud elements you can control - this article will provide you with details: Defining the ISMS scope if the servers are in the cloud https://advisera.com/27001academy/blog/2017/05/22/defining-the-isms-scope-if-the-servers-are-in-the-cloud/ 

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 29, 2020

Jan 29, 2020

Suggested Topics

Guest user Created:   Feb 21, 2022 ISO 27001 & 22301
Replies: 1
0 0

27001 question