Loading...
Loading...
Browse 3 real-world technical and behavioral interview questions about Iso 27001. Review scenarios, edge cases, and architectural best practices.
Say what the scope statement covers and what it does not, because a report or certificate covers named systems over a stated period and your newest service is probably in neither. The engineering job is keeping scope tied to the service catalogue so the answer is a lookup.
ISO 27001 certifies a management system against a fixed standard; SOC 2 is an attestation report whose scope you define and whose chosen controls a CPA firm opines on. Both separate the control from its implementation from the evidence, and only system-generated artefacts spanning the whole period count.
You inherit only the part the provider performs, and their report names the controls it assumes you operate yourself. Your evidence is their report plus your record that you checked its scope, period and complementary user entity controls, and then evidence for the configuration that remains yours.