Expert Advice Community

Guest

Statement of compliance

  Quote
Guest
Guest user Created:   Apr 15, 2017 Last commented:   Apr 15, 2017

Statement of compliance

My previous employer, whom I still support because they are a subsidiary of my current employer (xxxx), has asked me to help them to find and use or to draft an Executive Attestation Statement that they can provide to one of their major clients that will suffice for now to indicate that the company’s (xxxx) IT security policies and standards comply with ISO-27000 standards. They have not had a recent independent audit (such as an xxxx) or an ISO-27000 audit certification. The last xxxx audit they had was done in 2013.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 15, 2017

Do you have an executive attestation statement of compliance that they could use for now until the next ISO-27000 security audit occurs in August of this year? If they cannot provide an Executive Attestation at the very least, they may very well lose this client account.

Answer: Regarding ISO 27001, as an equivalent for an Executive Attestation Statement, you could recommend the use of the Statement of Applicability (you can see a free demo of this document at this link: https://advisera.com/27001academy/documentation/sta tement-of-applicability/ and see if it can fulfil his needs).

This article will provide you further explanation about the statement of applicability:
- The importance of Statement of Applicability for ISO 27001 https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/

These materials will also help you regarding the statement of applicability:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 14, 2017

Apr 14, 2017

Suggested Topics

Guest user Created:   Feb 20, 2017 ISO 27001 & 22301
Replies: 3
0 0

IGSOC