Search
Topics
  Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Downloads
· FAQ
· Feedback
· Forums
· Papers
· Statistics
· Surveys
· Top 10
· Topics
· Web Links
· Your Account

Who's Online
There are currently, 27 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

ISO17799 Search



Languages
Select Interface Language:


ISO 17799 Resources
There are now quite a few BS7799, ISO27001 and ISO 17799 portals on the web offering commercial tools & products. Possibly the most complete is ISO 17799 and ISO 27001 Central.

Call for Papers
We are shortly to launch a content section for papers and articles on ISO 17799 implementation, BS7799, AS4444, ISO 27001, UNE71502, and information security generally. If you have produced a paper and would like us to publish it, please contact us via the feedback form above.

ISO 27001, ISO 27002 & ISO17799 User Group: Forums

17799.Com :: View topic - Expected ISO27001 deliverables as a customer?
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Expected ISO27001 deliverables as a customer?

 
Post new topic   Reply to topic    17799.Com Forum Index -> ISO17799 Discussion and Debate
View previous topic :: View next topic  
Author Message
Manic
Newbie
Newbie


Joined: Nov 12, 2008
Posts: 1

PostPosted: Wed Nov 12, 2008 9:15 pm    Post subject: Expected ISO27001 deliverables as a customer? Reply with quote

The company I work for has outsourced operations to a provider who is contractually required to be ISO27001 certified.

As a customer, what am I entitled to view with regard to the initial certification and ongoing re-certification?

At present I have been provided with the Statement of Applicability and final certificate, however upon request for issues encountered, I was told that these are internal documents. Rolling Eyes

Advice appreciated.
Back to top
View user's profile
evajo
Newbie
Newbie


Joined: Jul 20, 2008
Posts: 4

PostPosted: Mon Nov 17, 2008 4:48 pm    Post subject: Reply with quote

according to this, your company belongs to External parties, and what restrict you and your action is based on the A6.2.1, A6.2.2, A6.2.3.
that's
"A.6.2.1 Identification of risks related to external parties
Control:The risks to the organization's information and information processing facilities from business processes involving external parties shall be identified and appropriate controls implemented before granting access.
A.6.2.2 Addressing security when dealing with customers
Control: All identified security requirements shall be addressed before giving customers access to the organization's information or assets.
A.6.2.3 Addressing security in third party agreements
Control:Agreements with third parties involving accessing, processing, communicating or managing the organization's information or information processing facilities, or adding products or services to information processing facilities shall cover all relevant security equirements."

and the Statement of Applicability and final certificate u mention is internal, but as your work need it, you can have it, and may some management restrict what you can do or not.
_________________
Jo Eva
CISSP
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic    17799.Com Forum Index -> ISO17799 Discussion and Debate All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Powered by phpBB 2.0.8 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem,
sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).

Version 2.1 by Nuke Cops © 2003 http://www.nukecops.com

Forums ©

 
The ISO 17799 Implementation Forum: A BS7799 / ISO27001, ISO17799 and ISO 27000 User Group
All logos and trademarks are property of their respective owner. Comments are property of their posters. The rest © 2005 ISO17799 / ISO 27002 Forum
AKA: BS 7799, SPE 20003, SS 627799, JIS X 5080, AS/NZS 4444, ISO 27001. Other links: UKAS accreditation body. SV
Website source phpnuke.org (c) 2003, and is Free Software under GNU / GPL licence. All Rights Are Reserved.