Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Should we aim for ISO27k conformance, alignment, compliance or certification?” A: Yes. Well OK, I guess you want some advice on which way to go?

0
10 Posted

Should we aim for ISO27k conformance, alignment, compliance or certification?” A: Yes. Well OK, I guess you want some advice on which way to go?

0
10

• Conformance (meaning a general intent to apply the ISO27k standards) is a basic starting point, achievable at little cost for any organization that takes information security seriously. However, the ‘general intent’ bit implies a fair amount of management discretion about which specific parts of the ISO27k set are going to be used, and more importantly to what extent they are to be adopted. Conformance gives little if any assurance to third parties about the organization’s information security status. It’s practically meaningless without further information (for example which ISO27k standards have been implemented, and to what extent? Is the organization merely planning to adopt the ISO27k standards at some future point, or has it already done so?). • Alignment is about as worthless as conformance. It could mean practically anything. • Compliance (meaning a more rigorous, comprehensive and systematic adoption of the ISO27k standards) is the next level which typically involves the org

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.