Expert Advice Community

Guest

SoA changes

  Quote
Guest
Guest user Created:   Nov 14, 2018 Last commented:   Nov 14, 2018

SoA changes

I was told from an auditor that an SoA cannot be changed during the 3 year valid period after the certification has been achieved (need to have the same version number and date as the same used for the certification). If this is being changed, then the scope (security controls) has changes and the existing certificate will not be valid
0 0

Assign topic to the user

ISO 27001 STATEMENT OF APPLICABILITY

List all controls and determine which are applicable and why.

ISO 27001 STATEMENT OF APPLICABILITY

List all controls and determine which are applicable and why.

Expert
Rhand Leal Nov 14, 2018

If an external auditor reveals any changes to the SoA during e.g. a surveillance audit, the certification will not be valid and a new certification process needs to be stated since the scope has changed. My understanding that an SOA is a working document that should be updated as needed as the business changes. Can you let me know which is correct and point to reference material that describes this?

Answer:

Your understanding about SoA is correct. This is a living document that must be updated as needed. Sometimes this need to update is to reflect changes in risks not necessarily related to changes in the scope. In this case you have to record the decision made to update the SoA, and related information (e.g., update the risk assessment regarding the new risks). During a surveillance audit, the auditor will verify if the change in the SoA was done according the standard requirements and implemented documentation.

When changes in the SoA are in fact related to changes in the scope, besides the previous mentioned steps, you have to communicate this situation to your certification body so you can define how to approach this situation, because the certification scope will have to be updated. In some cases this will require an immediate surveillance audit, but in most cases this can be verified on the next external audit. For the additional scope you have to ensure the same steps taken that were performed to implement the ISMS.

This article will provide you further explanation about SoA:
- The importance of Statement of Applicability for ISO 27001 https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 14, 2018

Nov 14, 2018