<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: scopes]]></title>
    <link>http://securityratty.com/tag/scopes</link>
    <description></description>
    <pubDate>Tue, 20 May 2008 13:31:23 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[How Do I Get ISO27001 Certification?]]></title>
      <link>http://securityratty.com/article/1dfa014f9222e43976da535278f9636b</link>
      <guid>http://securityratty.com/article/1dfa014f9222e43976da535278f9636b</guid>
      <description><![CDATA[Everybody has heard of the international standard ISO 27001 (or at least of its U.K. predecessor, BS7799-2). Now, more and more people wonder: How do I get a certificate for my organization? While in...]]></description>
      <content:encoded><![CDATA[Everybody has heard of the international standard ISO 27001 (or at least of its U.K. predecessor, BS7799-2). Now, more and more people wonder: How do I get a certificate for my organization? While in some countries (such as the U.K. and Germany), it's more common to get a certificate, in the U.S. it's not. Well, there are two ways to approach this: Find an accredited auditor (person), or find an accredited certification body (organization).<br />
<br />
Auditors must be accredited by the International Register of Certificated Auditors (IRCA), so <a href="http://www.irca.org/">www.irca.org</a> is a good starting point. For example, you'll find 40 auditors in the U.S. who are accredited for ISO 27001. They work for large consultancies or system integrators, but also for some smaller companies. Alternatively, you can look for an organization that issues certificates. Unfortunately, there is no international register for them; you'll have to look for a certifying organization that is accredited by a national accreditation body (for example, UKAS in the U.K. or TGA in Germany). These bodies maintain a list of accredited organizations (see <a href="http://www.ukas.com/about_accreditation/accredited_bodies/certification_body_schedules.asp">http://www.ukas.com/about_accreditation/accredited_bodies/certification_body_schedules.asp</a> and <a href="http://www.tga-gmbh.de/scopes/index.php?id=0051">http://www.tga-gmbh.de/scopes/index.php?id=0051</a>). For other countries, see the member list in <a href="http://www.iaf.nu">http://www.iaf.nu</a>. In the U.S., ANSI is in charge and has delegated this responsibility to ANAB (American National Standards Institute - American Society for Quality National Accreditation Board). However, the corresponding database (see <a href="http://www.anab.org/Directory/Certs_Search.asp">http://www.anab.org/Directory/Certs_Search.asp</a>) lists only two accredited organizations. The better way is probably to either look at the U.K. register (because many organizations can issue certificates for companies in the U.S. as well) or have a look at the unofficial register of ISO 27001 certificates (see <a href="http://www.iso27001certificates.com">http://www.iso27001certificates.com</a>). There, you'll find a list of certified companies and the corresponding body that issued the certificate.<br />
<br />
No matter which entry point you choose, the list of auditors, the list of certifying organizations or the list of issued certificates - the names that come up are often the same: BSI Management Systems, one of the TÜV companies, PricewaterhouseCoopers, Bureau Veritas and Atsec.<br />
<br />
]]></content:encoded>
      <pubDate>Tue, 20 May 2008 13:31:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/certification body">certification body</category>
      <category domain="http://securityratty.com/tag/body">body</category>
      <category domain="http://securityratty.com/tag/register">register</category>
      <category domain="http://securityratty.com/tag/international register">international register</category>
      <category domain="http://securityratty.com/tag/body schedules">body schedules</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/international standard iso">international standard iso</category>
      <category domain="http://securityratty.com/tag/tv companies">tv companies</category>
      <category domain="http://securityratty.com/tag/iso">iso</category>
      <source url="http://blog.gartner.com/blog/security.php?x=0&amp;itemid=3526">How Do I Get ISO27001 Certification?</source>
    </item>
  </channel>
</rss>
