SlideShare a Scribd company logo
1 of 3
Download to read offline
IT ADVISORY
KPMG ADVISORY

How to effectively use ISO 27001 Certification and
Service Organization Control (SOC2) Reports
Increase Assurance over Outsourced controls regarding Security, Availability
and Confidentiality.
You are a service organization managing clients’ mission critical systems, storing
and processing confidential client information for multiple clients

The challenge

Your benefits

KPMG Approach

Contact

The challenge
•	

Information security is front page news across the globe, with a constant
flow of new breaches, hacks and incidents undermining public confidence
in the ability of organizations to keep their data safe.

•	

Industry regulators are focusing their energies on ensuring that
organizations take the emerging threats seriously and that information
security is scrutinized at the highest level in an organization.

•	

Your clients are becoming increasingly sensitive to the measures taken
to protect their confidential information and to ensure availability of their
systems.

•	

D
	 eficiencies in the security offered by you may result in the release of client
information and lead to reputational damage both to you and your clients.

•	

Real or perceived security breaches may cause your clients to believe that
your organization is unable to conduct business securely and responsibly.

•	

Clients are demanding insight in your system and related controls, design
and control implementation, as well as assurance regarding the operating
effectiveness of these controls.

•	

You are confronted with multiple visits of clients’ auditors and requests to
complete detailed security questionnaires or checklists about your controls
environment.

•	

You must demonstrate your capability to meet your clients’ compliance
needs and strengthen their confidence in your ability.

•	

A
	 n ISO 27001 certification is proof of your capability of maintaining an
effective Information Security Management System to a broad public,
including Industry Regulators and your current and future clients.

Your benefits
•	

A SOC2 report based on the ISO 27001 Control Objectives has the same
look and feel as a SOC1 report (ISAE 3402 report, formerly known as SAS
70 report) and provides your clients with sufficient information (independent
service auditor’s opinion, management assertion, system description, tests
performed by service auditor and test results) to meet their assurance
needs.

•	

The integration of the ISO 27001 certification with the SOC2 reporting
allows us to perform the audit in a more efficient manner (“multi-purpose
testing”) and enables us to pass on these cost savings and reduction in
number of audit days to you; in addition this will significantly reduce the
burden on your internal resources.

Competitive Advantage /
Necessity

Reduced Effort
Supporting
Client-Specific Security
Questionnaires / Audits

Increased Internal
Assurance Regarding
Security and Related
Controls

Proactive Response to
Customer Oversight of
Security, Privacy,
and Data Risks

KPMG Approach
KPMG offers an integrated assurance approach that allows us to efficiently
perform the ISO 27001 certification and SOC2 reporting in a single assessment.
This integrated approach has the following phases:

Diagnostic Review
For service organizations that are new to the ISO 27001 certification and/or SOC2
reporting process, we recommend that a “Diagnostic Review” be performed.
The purposes of the review are to perform a gap analysis against ISO 27001 and
identify areas that require attention prior to beginning the formal certification.
In addition, during a Diagnostic Review, we will assist you in identifying and
documenting your controls for the SOC2 report. This is ordinarily a significant
component of management’s effort during a first year report.

ISO 27001 certification
We have a tried and tested methodology to perform certification audits efficiently.
There is an initial certification assessment that includes auditing all of the controls
in the standard, followed by regular surveillance audits over a three year period. To
maintain the certification there is a full re-assessment every three years.
SOC 2 Type I report on management’s description of the system and
the suitability of design of controls
Based on the work performed for the initial ISO 27001 certification, a SOC2 Type
I report is prepared.
A Type I report contains the service organization’s description of its system at a
specific point in time. In a Type I report, the service auditor will express an opinion
on (1) whether management’s description of its system fairly presents the system
that was designed and implemented as of a specific date and (2) whether the
controls stated in management’s description of its system were suitably designed
to meet the ISO 27001 control objectives as of a specified date. An initial Type I
report normally serves as the starting point for subsequent Type II examinations.

SOC2 Type II report on management’s description of the system and
the suitability of the design and operating effectiveness of controls.
A Type II report contains the service organization’s description of controls during
a defined period of time. In a Type II report, the service auditor will express an
opinion on the two items included in a Type I report, as well as whether the controls
operated effectively throughout the specified period to meet the applicable ISO
27001 control objectives. A Type II report includes not only the service organization’s
management assertion and description of its system but also detailed results of
testing of the service organization’s control over the specified period of time.
ISO 27001 Surveillance Audits and Re-Assessment Audits
The ISO 27001 Surveillance Audits and Re-Assessment Audits (every three years)
will leverage to a large extent on the work done as part of the annual SOC2 Type
II reporting.

CREDENTIALS
KPMG is a global leader in delivering Service Organization Control (SOC) reporting
services. KPMG’s IT Attestation practice consists of a globally accredited network
of partners and professional staff who provide a range of IT attestation services
to help organizations satisfy their third-party assurance requirements. We have
established a global accreditation process to help ensure consistency and quality
in the delivery of attestation and assurance services including SOC1 and SOC 2
examinations and Agreed Upon Procedures. We have over 1,000 professionals
fully trained in the SOC examination process through our global IT Attestation
Instructor network.
KPMG has a team of trained ISO 27001 lead auditors with extensive experience
of performing certifications across all industry sectors. KPMG has a Certification
Body that is accredited by the United Kingdom Accreditation Service (UKAS) to
perform ISO 27001 certifications globally.

contact
Stephan Claes

Dirk Timmerman

Partner
KPMG IT Advisory

Executive Director
KPMG IT Advisory

T: +32 2 708 48 50
E: sclaes3@kpmg.com

T: +32 2 708 43 59
E: dtimmerman@kpmg.com

© 2013 KPMG Advisory, a Belgian civil CVBA/SCRL and a member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative
(“KPMG International”), a Swiss entity. All rights reserved. Printed in Belgium.

More Related Content

What's hot

NQA ISO 22000 Food Safety Transition Gap Guide
NQA ISO 22000 Food Safety Transition Gap GuideNQA ISO 22000 Food Safety Transition Gap Guide
NQA ISO 22000 Food Safety Transition Gap GuideNQA
 
ISO 27001 Checklist - Management Review - Clause 9.3 - 59 checklist Questions
ISO 27001 Checklist - Management Review - Clause 9.3 - 59 checklist QuestionsISO 27001 Checklist - Management Review - Clause 9.3 - 59 checklist Questions
ISO 27001 Checklist - Management Review - Clause 9.3 - 59 checklist Questionshimalya sharma
 
ISO 27001 Checklist - information Security risk management- clause 6.1.1, 6.1...
ISO 27001 Checklist - information Security risk management- clause 6.1.1, 6.1...ISO 27001 Checklist - information Security risk management- clause 6.1.1, 6.1...
ISO 27001 Checklist - information Security risk management- clause 6.1.1, 6.1...himalya sharma
 
ISO 27001 Checklist - Continual Improvement - Clause 10.2 - 63 checklist Que...
ISO  27001 Checklist - Continual Improvement - Clause 10.2 - 63 checklist Que...ISO  27001 Checklist - Continual Improvement - Clause 10.2 - 63 checklist Que...
ISO 27001 Checklist - Continual Improvement - Clause 10.2 - 63 checklist Que...himalya sharma
 
ISO 20000-1:2018 Awareness and Auditor Training PPT Presentation kit for ITSM
ISO 20000-1:2018 Awareness and Auditor Training PPT Presentation kit for ITSMISO 20000-1:2018 Awareness and Auditor Training PPT Presentation kit for ITSM
ISO 20000-1:2018 Awareness and Auditor Training PPT Presentation kit for ITSMGlobal Manager Group
 
ISO 27001 checklist - Leadership and Commitment - clause 5.1 - 70 checklist Q...
ISO 27001 checklist - Leadership and Commitment - clause 5.1 - 70 checklist Q...ISO 27001 checklist - Leadership and Commitment - clause 5.1 - 70 checklist Q...
ISO 27001 checklist - Leadership and Commitment - clause 5.1 - 70 checklist Q...himalya sharma
 
Lynda Cooper: ISO/IEC 20000 - The Launch of the Revised Standard
Lynda Cooper: ISO/IEC 20000 - The Launch of the Revised StandardLynda Cooper: ISO/IEC 20000 - The Launch of the Revised Standard
Lynda Cooper: ISO/IEC 20000 - The Launch of the Revised StandarditSMF UK
 
ISO 27001 Checklist - Operation - Clause 8 ( 8.1, 8.2, 8.3 ) - 95 checklist Q...
ISO 27001 Checklist - Operation - Clause 8 ( 8.1, 8.2, 8.3 ) - 95 checklist Q...ISO 27001 Checklist - Operation - Clause 8 ( 8.1, 8.2, 8.3 ) - 95 checklist Q...
ISO 27001 Checklist - Operation - Clause 8 ( 8.1, 8.2, 8.3 ) - 95 checklist Q...himalya sharma
 
Benefits of Integrating ISO and CMMI Service Management System Frameworks
Benefits of Integrating ISO and CMMI Service Management System FrameworksBenefits of Integrating ISO and CMMI Service Management System Frameworks
Benefits of Integrating ISO and CMMI Service Management System FrameworksIntegration Technologies Group Inc
 
New Microsoft PowerPoint Presentation
New Microsoft PowerPoint PresentationNew Microsoft PowerPoint Presentation
New Microsoft PowerPoint PresentationMohammed Ghorab
 
Iso 20000 standard implementation
Iso 20000 standard implementationIso 20000 standard implementation
Iso 20000 standard implementationIITSW Company
 
ISO 27001 Checklist - Nonconformity and Corrective Action - Clause 10.1 - 53...
 ISO 27001 Checklist - Nonconformity and Corrective Action - Clause 10.1 - 53... ISO 27001 Checklist - Nonconformity and Corrective Action - Clause 10.1 - 53...
ISO 27001 Checklist - Nonconformity and Corrective Action - Clause 10.1 - 53...himalya sharma
 
PECB Webinar: Winning approach towards successful ISO/IEC 20000 Certification
PECB Webinar: Winning approach towards successful ISO/IEC 20000 CertificationPECB Webinar: Winning approach towards successful ISO/IEC 20000 Certification
PECB Webinar: Winning approach towards successful ISO/IEC 20000 CertificationPECB
 
ISO 27001 Checklist - Internal Audit - Clause 9.2 - 59 checklist Questions
ISO 27001 Checklist - Internal Audit - Clause 9.2 - 59 checklist QuestionsISO 27001 Checklist - Internal Audit - Clause 9.2 - 59 checklist Questions
ISO 27001 Checklist - Internal Audit - Clause 9.2 - 59 checklist Questionshimalya sharma
 
Benefits of Implementing ISO 20000 within your Organization
 Benefits of Implementing ISO 20000 within your Organization Benefits of Implementing ISO 20000 within your Organization
Benefits of Implementing ISO 20000 within your OrganizationPECB
 
IT Security | IT Audit | IT Security Audit | IT security audit Checklist | 12...
IT Security | IT Audit | IT Security Audit | IT security audit Checklist | 12...IT Security | IT Audit | IT Security Audit | IT security audit Checklist | 12...
IT Security | IT Audit | IT Security Audit | IT security audit Checklist | 12...himalya sharma
 
ITSM Foundation Course Material
ITSM Foundation Course MaterialITSM Foundation Course Material
ITSM Foundation Course Materialstefanhenry
 

What's hot (20)

Iso 20000 presentation
Iso 20000 presentationIso 20000 presentation
Iso 20000 presentation
 
NQA ISO 22000 Food Safety Transition Gap Guide
NQA ISO 22000 Food Safety Transition Gap GuideNQA ISO 22000 Food Safety Transition Gap Guide
NQA ISO 22000 Food Safety Transition Gap Guide
 
ISO 27001 Checklist - Management Review - Clause 9.3 - 59 checklist Questions
ISO 27001 Checklist - Management Review - Clause 9.3 - 59 checklist QuestionsISO 27001 Checklist - Management Review - Clause 9.3 - 59 checklist Questions
ISO 27001 Checklist - Management Review - Clause 9.3 - 59 checklist Questions
 
ISO 27001 Checklist - information Security risk management- clause 6.1.1, 6.1...
ISO 27001 Checklist - information Security risk management- clause 6.1.1, 6.1...ISO 27001 Checklist - information Security risk management- clause 6.1.1, 6.1...
ISO 27001 Checklist - information Security risk management- clause 6.1.1, 6.1...
 
ISO 27001 Checklist - Continual Improvement - Clause 10.2 - 63 checklist Que...
ISO  27001 Checklist - Continual Improvement - Clause 10.2 - 63 checklist Que...ISO  27001 Checklist - Continual Improvement - Clause 10.2 - 63 checklist Que...
ISO 27001 Checklist - Continual Improvement - Clause 10.2 - 63 checklist Que...
 
ISO 20000-1:2018 Awareness and Auditor Training PPT Presentation kit for ITSM
ISO 20000-1:2018 Awareness and Auditor Training PPT Presentation kit for ITSMISO 20000-1:2018 Awareness and Auditor Training PPT Presentation kit for ITSM
ISO 20000-1:2018 Awareness and Auditor Training PPT Presentation kit for ITSM
 
ISO 27001 checklist - Leadership and Commitment - clause 5.1 - 70 checklist Q...
ISO 27001 checklist - Leadership and Commitment - clause 5.1 - 70 checklist Q...ISO 27001 checklist - Leadership and Commitment - clause 5.1 - 70 checklist Q...
ISO 27001 checklist - Leadership and Commitment - clause 5.1 - 70 checklist Q...
 
Lynda Cooper: ISO/IEC 20000 - The Launch of the Revised Standard
Lynda Cooper: ISO/IEC 20000 - The Launch of the Revised StandardLynda Cooper: ISO/IEC 20000 - The Launch of the Revised Standard
Lynda Cooper: ISO/IEC 20000 - The Launch of the Revised Standard
 
ISO 27001 Checklist - Operation - Clause 8 ( 8.1, 8.2, 8.3 ) - 95 checklist Q...
ISO 27001 Checklist - Operation - Clause 8 ( 8.1, 8.2, 8.3 ) - 95 checklist Q...ISO 27001 Checklist - Operation - Clause 8 ( 8.1, 8.2, 8.3 ) - 95 checklist Q...
ISO 27001 Checklist - Operation - Clause 8 ( 8.1, 8.2, 8.3 ) - 95 checklist Q...
 
Benefits of Integrating ISO and CMMI Service Management System Frameworks
Benefits of Integrating ISO and CMMI Service Management System FrameworksBenefits of Integrating ISO and CMMI Service Management System Frameworks
Benefits of Integrating ISO and CMMI Service Management System Frameworks
 
Iso 20000 itsms implementation steps-lakshy
Iso 20000    itsms implementation steps-lakshyIso 20000    itsms implementation steps-lakshy
Iso 20000 itsms implementation steps-lakshy
 
New Microsoft PowerPoint Presentation
New Microsoft PowerPoint PresentationNew Microsoft PowerPoint Presentation
New Microsoft PowerPoint Presentation
 
Iso 20000 standard implementation
Iso 20000 standard implementationIso 20000 standard implementation
Iso 20000 standard implementation
 
ISO 27001 Checklist - Nonconformity and Corrective Action - Clause 10.1 - 53...
 ISO 27001 Checklist - Nonconformity and Corrective Action - Clause 10.1 - 53... ISO 27001 Checklist - Nonconformity and Corrective Action - Clause 10.1 - 53...
ISO 27001 Checklist - Nonconformity and Corrective Action - Clause 10.1 - 53...
 
PECB Webinar: Winning approach towards successful ISO/IEC 20000 Certification
PECB Webinar: Winning approach towards successful ISO/IEC 20000 CertificationPECB Webinar: Winning approach towards successful ISO/IEC 20000 Certification
PECB Webinar: Winning approach towards successful ISO/IEC 20000 Certification
 
New ISO 20000-1:2018 Changes, Implementation Steps
New ISO 20000-1:2018 Changes, Implementation StepsNew ISO 20000-1:2018 Changes, Implementation Steps
New ISO 20000-1:2018 Changes, Implementation Steps
 
ISO 27001 Checklist - Internal Audit - Clause 9.2 - 59 checklist Questions
ISO 27001 Checklist - Internal Audit - Clause 9.2 - 59 checklist QuestionsISO 27001 Checklist - Internal Audit - Clause 9.2 - 59 checklist Questions
ISO 27001 Checklist - Internal Audit - Clause 9.2 - 59 checklist Questions
 
Benefits of Implementing ISO 20000 within your Organization
 Benefits of Implementing ISO 20000 within your Organization Benefits of Implementing ISO 20000 within your Organization
Benefits of Implementing ISO 20000 within your Organization
 
IT Security | IT Audit | IT Security Audit | IT security audit Checklist | 12...
IT Security | IT Audit | IT Security Audit | IT security audit Checklist | 12...IT Security | IT Audit | IT Security Audit | IT security audit Checklist | 12...
IT Security | IT Audit | IT Security Audit | IT security audit Checklist | 12...
 
ITSM Foundation Course Material
ITSM Foundation Course MaterialITSM Foundation Course Material
ITSM Foundation Course Material
 

Viewers also liked

Iso 27001 2013 Standard Requirements
Iso 27001 2013 Standard RequirementsIso 27001 2013 Standard Requirements
Iso 27001 2013 Standard RequirementsUppala Anand
 
Iso 27001 metrics and implementation guide
Iso 27001 metrics and implementation guideIso 27001 metrics and implementation guide
Iso 27001 metrics and implementation guidemfmurat
 
22000 FSMS Action Plan
22000 FSMS Action Plan22000 FSMS Action Plan
22000 FSMS Action PlanCynthia Weber
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewNaresh Rao
 
Scs Corporate Profile
Scs Corporate ProfileScs Corporate Profile
Scs Corporate ProfileSCS universal
 
Iso 22000 standard requirements
Iso 22000 standard requirementsIso 22000 standard requirements
Iso 22000 standard requirementsHenry Nelson
 
ISO 27001 Implementation_Documentation_Mandatory_List
ISO 27001 Implementation_Documentation_Mandatory_ListISO 27001 Implementation_Documentation_Mandatory_List
ISO 27001 Implementation_Documentation_Mandatory_ListSriramITISConsultant
 
ISO 27001:2013 Implementation procedure
ISO 27001:2013 Implementation procedureISO 27001:2013 Implementation procedure
ISO 27001:2013 Implementation procedureUppala Anand
 
ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3Tanmay Shinde
 
ISO/IEC 27001:2013 An Overview
ISO/IEC 27001:2013  An Overview ISO/IEC 27001:2013  An Overview
ISO/IEC 27001:2013 An Overview Ahmed Riad .
 
Iso 22000 At Dfc Idf 110309 Final 180209
Iso 22000 At Dfc Idf   110309   Final   180209Iso 22000 At Dfc Idf   110309   Final   180209
Iso 22000 At Dfc Idf 110309 Final 180209MonachusConsulting
 
Difference between HACCP and ISO 22000
Difference between HACCP and ISO 22000Difference between HACCP and ISO 22000
Difference between HACCP and ISO 22000PECB
 
ISO 22000: 2005 for Bakery industry
ISO 22000: 2005 for Bakery industryISO 22000: 2005 for Bakery industry
ISO 22000: 2005 for Bakery industryRavi Damani
 
UX, ethnography and possibilities: for Libraries, Museums and Archives
UX, ethnography and possibilities: for Libraries, Museums and ArchivesUX, ethnography and possibilities: for Libraries, Museums and Archives
UX, ethnography and possibilities: for Libraries, Museums and ArchivesNed Potter
 

Viewers also liked (17)

Iso 27001 2013 Standard Requirements
Iso 27001 2013 Standard RequirementsIso 27001 2013 Standard Requirements
Iso 27001 2013 Standard Requirements
 
Iso 27001 metrics and implementation guide
Iso 27001 metrics and implementation guideIso 27001 metrics and implementation guide
Iso 27001 metrics and implementation guide
 
22000 FSMS Action Plan
22000 FSMS Action Plan22000 FSMS Action Plan
22000 FSMS Action Plan
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overview
 
Scs Corporate Profile
Scs Corporate ProfileScs Corporate Profile
Scs Corporate Profile
 
Iso 22000 standard requirements
Iso 22000 standard requirementsIso 22000 standard requirements
Iso 22000 standard requirements
 
Infosec Audit Lecture_4
Infosec Audit Lecture_4Infosec Audit Lecture_4
Infosec Audit Lecture_4
 
ISO 27001 Implementation_Documentation_Mandatory_List
ISO 27001 Implementation_Documentation_Mandatory_ListISO 27001 Implementation_Documentation_Mandatory_List
ISO 27001 Implementation_Documentation_Mandatory_List
 
Manual haccp iso 22000
Manual haccp iso 22000Manual haccp iso 22000
Manual haccp iso 22000
 
ISO 27001:2013 Implementation procedure
ISO 27001:2013 Implementation procedureISO 27001:2013 Implementation procedure
ISO 27001:2013 Implementation procedure
 
ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3
 
ISO/IEC 27001:2013 An Overview
ISO/IEC 27001:2013  An Overview ISO/IEC 27001:2013  An Overview
ISO/IEC 27001:2013 An Overview
 
Iso 22000 At Dfc Idf 110309 Final 180209
Iso 22000 At Dfc Idf   110309   Final   180209Iso 22000 At Dfc Idf   110309   Final   180209
Iso 22000 At Dfc Idf 110309 Final 180209
 
Difference between HACCP and ISO 22000
Difference between HACCP and ISO 22000Difference between HACCP and ISO 22000
Difference between HACCP and ISO 22000
 
ISO 22000: 2005 for Bakery industry
ISO 22000: 2005 for Bakery industryISO 22000: 2005 for Bakery industry
ISO 22000: 2005 for Bakery industry
 
UX, ethnography and possibilities: for Libraries, Museums and Archives
UX, ethnography and possibilities: for Libraries, Museums and ArchivesUX, ethnography and possibilities: for Libraries, Museums and Archives
UX, ethnography and possibilities: for Libraries, Museums and Archives
 
Build Features, Not Apps
Build Features, Not AppsBuild Features, Not Apps
Build Features, Not Apps
 

Similar to How to effectively use ISO 27001 Certification and SOC 2 Reports

Soc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organizationSoc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organizationVISTA InfoSec
 
Soc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-convertedSoc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-convertedVISTA InfoSec
 
SOC 2 Compliance and Certification
SOC 2 Compliance and CertificationSOC 2 Compliance and Certification
SOC 2 Compliance and CertificationControlCase
 
A Beginner's Guide to SOC 2 Certification
A Beginner's Guide to SOC 2 CertificationA Beginner's Guide to SOC 2 Certification
A Beginner's Guide to SOC 2 CertificationShyamMishra72
 
ISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdfISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdfControlCase
 
SOC 2 certification: a Comprehensive Guide
SOC 2 certification: a Comprehensive GuideSOC 2 certification: a Comprehensive Guide
SOC 2 certification: a Comprehensive GuideShyamMishra72
 
✅ WHY IS ISO 20000-1 CERTIFICATION A GOOD IDEA FOR YOUR ORGANIZATION GROWTH?
✅ WHY IS ISO 20000-1 CERTIFICATION A GOOD IDEA FOR YOUR ORGANIZATION GROWTH?✅ WHY IS ISO 20000-1 CERTIFICATION A GOOD IDEA FOR YOUR ORGANIZATION GROWTH?
✅ WHY IS ISO 20000-1 CERTIFICATION A GOOD IDEA FOR YOUR ORGANIZATION GROWTH?sistemaCertification
 
Internal Control Certification – It’s Not Just an Accounting Thing (Credit Un...
Internal Control Certification – It’s Not Just an Accounting Thing (Credit Un...Internal Control Certification – It’s Not Just an Accounting Thing (Credit Un...
Internal Control Certification – It’s Not Just an Accounting Thing (Credit Un...NAFCU Services Corporation
 
Account Right SOC Services brochure.pptx
Account Right SOC Services brochure.pptxAccount Right SOC Services brochure.pptx
Account Right SOC Services brochure.pptxGaneshMeenakshiSunda4
 
Health, Safety and Security through Compliance
Health, Safety and Security through ComplianceHealth, Safety and Security through Compliance
Health, Safety and Security through Compliancekanew396
 
Certificat iso 9001
Certificat iso 9001Certificat iso 9001
Certificat iso 9001statebagia
 
Auditor Reporting on Controls at Service Organizations
Auditor Reporting on Controls at Service OrganizationsAuditor Reporting on Controls at Service Organizations
Auditor Reporting on Controls at Service OrganizationsUniversity of Waterloo
 
TQM- Quality management system
TQM- Quality management systemTQM- Quality management system
TQM- Quality management systemZubair Memon
 
Iso 9001 guide
Iso 9001 guideIso 9001 guide
Iso 9001 guidenobbys303
 
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...acinfotec
 
Relevance of iso management systems certification
Relevance of iso management systems certificationRelevance of iso management systems certification
Relevance of iso management systems certificationAbdulkadir Jelani Abubakar
 
Quality management system services 'QMS' in India
Quality management system services 'QMS' in IndiaQuality management system services 'QMS' in India
Quality management system services 'QMS' in IndiaManojHosur
 

Similar to How to effectively use ISO 27001 Certification and SOC 2 Reports (20)

Soc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organizationSoc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organization
 
Soc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-convertedSoc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-converted
 
SOC 2 Compliance and Certification
SOC 2 Compliance and CertificationSOC 2 Compliance and Certification
SOC 2 Compliance and Certification
 
A Beginner's Guide to SOC 2 Certification
A Beginner's Guide to SOC 2 CertificationA Beginner's Guide to SOC 2 Certification
A Beginner's Guide to SOC 2 Certification
 
ISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdfISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdf
 
SOC 2 certification: a Comprehensive Guide
SOC 2 certification: a Comprehensive GuideSOC 2 certification: a Comprehensive Guide
SOC 2 certification: a Comprehensive Guide
 
✅ WHY IS ISO 20000-1 CERTIFICATION A GOOD IDEA FOR YOUR ORGANIZATION GROWTH?
✅ WHY IS ISO 20000-1 CERTIFICATION A GOOD IDEA FOR YOUR ORGANIZATION GROWTH?✅ WHY IS ISO 20000-1 CERTIFICATION A GOOD IDEA FOR YOUR ORGANIZATION GROWTH?
✅ WHY IS ISO 20000-1 CERTIFICATION A GOOD IDEA FOR YOUR ORGANIZATION GROWTH?
 
Internal Control Certification – It’s Not Just an Accounting Thing (Credit Un...
Internal Control Certification – It’s Not Just an Accounting Thing (Credit Un...Internal Control Certification – It’s Not Just an Accounting Thing (Credit Un...
Internal Control Certification – It’s Not Just an Accounting Thing (Credit Un...
 
SOC Certification.pdf
SOC Certification.pdfSOC Certification.pdf
SOC Certification.pdf
 
Account Right SOC Services brochure.pptx
Account Right SOC Services brochure.pptxAccount Right SOC Services brochure.pptx
Account Right SOC Services brochure.pptx
 
Health, Safety and Security through Compliance
Health, Safety and Security through ComplianceHealth, Safety and Security through Compliance
Health, Safety and Security through Compliance
 
Certificat iso 9001
Certificat iso 9001Certificat iso 9001
Certificat iso 9001
 
Auditor Reporting on Controls at Service Organizations
Auditor Reporting on Controls at Service OrganizationsAuditor Reporting on Controls at Service Organizations
Auditor Reporting on Controls at Service Organizations
 
TQM- Quality management system
TQM- Quality management systemTQM- Quality management system
TQM- Quality management system
 
Damco iso 27001
Damco iso   27001Damco iso   27001
Damco iso 27001
 
Iso 9001 guide
Iso 9001 guideIso 9001 guide
Iso 9001 guide
 
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...
 
Relevance of iso management systems certification
Relevance of iso management systems certificationRelevance of iso management systems certification
Relevance of iso management systems certification
 
Quality management system services 'QMS' in India
Quality management system services 'QMS' in IndiaQuality management system services 'QMS' in India
Quality management system services 'QMS' in India
 
ISO 9001 2008 Part I
ISO 9001 2008 Part IISO 9001 2008 Part I
ISO 9001 2008 Part I
 

Recently uploaded

Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Hyundai Motor Group
 
How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?XfilesPro
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphNeo4j
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetHyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetEnjoy Anytime
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 

Recently uploaded (20)

Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2
 
How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetHyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 

How to effectively use ISO 27001 Certification and SOC 2 Reports

  • 1. IT ADVISORY KPMG ADVISORY How to effectively use ISO 27001 Certification and Service Organization Control (SOC2) Reports Increase Assurance over Outsourced controls regarding Security, Availability and Confidentiality. You are a service organization managing clients’ mission critical systems, storing and processing confidential client information for multiple clients The challenge Your benefits KPMG Approach Contact The challenge • Information security is front page news across the globe, with a constant flow of new breaches, hacks and incidents undermining public confidence in the ability of organizations to keep their data safe. • Industry regulators are focusing their energies on ensuring that organizations take the emerging threats seriously and that information security is scrutinized at the highest level in an organization. • Your clients are becoming increasingly sensitive to the measures taken to protect their confidential information and to ensure availability of their systems. • D eficiencies in the security offered by you may result in the release of client information and lead to reputational damage both to you and your clients. • Real or perceived security breaches may cause your clients to believe that your organization is unable to conduct business securely and responsibly. • Clients are demanding insight in your system and related controls, design and control implementation, as well as assurance regarding the operating effectiveness of these controls. • You are confronted with multiple visits of clients’ auditors and requests to complete detailed security questionnaires or checklists about your controls environment. • You must demonstrate your capability to meet your clients’ compliance needs and strengthen their confidence in your ability. • A n ISO 27001 certification is proof of your capability of maintaining an effective Information Security Management System to a broad public, including Industry Regulators and your current and future clients. Your benefits
  • 2. • A SOC2 report based on the ISO 27001 Control Objectives has the same look and feel as a SOC1 report (ISAE 3402 report, formerly known as SAS 70 report) and provides your clients with sufficient information (independent service auditor’s opinion, management assertion, system description, tests performed by service auditor and test results) to meet their assurance needs. • The integration of the ISO 27001 certification with the SOC2 reporting allows us to perform the audit in a more efficient manner (“multi-purpose testing”) and enables us to pass on these cost savings and reduction in number of audit days to you; in addition this will significantly reduce the burden on your internal resources. Competitive Advantage / Necessity Reduced Effort Supporting Client-Specific Security Questionnaires / Audits Increased Internal Assurance Regarding Security and Related Controls Proactive Response to Customer Oversight of Security, Privacy, and Data Risks KPMG Approach KPMG offers an integrated assurance approach that allows us to efficiently perform the ISO 27001 certification and SOC2 reporting in a single assessment. This integrated approach has the following phases: Diagnostic Review For service organizations that are new to the ISO 27001 certification and/or SOC2 reporting process, we recommend that a “Diagnostic Review” be performed. The purposes of the review are to perform a gap analysis against ISO 27001 and identify areas that require attention prior to beginning the formal certification. In addition, during a Diagnostic Review, we will assist you in identifying and documenting your controls for the SOC2 report. This is ordinarily a significant component of management’s effort during a first year report. ISO 27001 certification We have a tried and tested methodology to perform certification audits efficiently. There is an initial certification assessment that includes auditing all of the controls in the standard, followed by regular surveillance audits over a three year period. To maintain the certification there is a full re-assessment every three years. SOC 2 Type I report on management’s description of the system and the suitability of design of controls Based on the work performed for the initial ISO 27001 certification, a SOC2 Type I report is prepared.
  • 3. A Type I report contains the service organization’s description of its system at a specific point in time. In a Type I report, the service auditor will express an opinion on (1) whether management’s description of its system fairly presents the system that was designed and implemented as of a specific date and (2) whether the controls stated in management’s description of its system were suitably designed to meet the ISO 27001 control objectives as of a specified date. An initial Type I report normally serves as the starting point for subsequent Type II examinations. SOC2 Type II report on management’s description of the system and the suitability of the design and operating effectiveness of controls. A Type II report contains the service organization’s description of controls during a defined period of time. In a Type II report, the service auditor will express an opinion on the two items included in a Type I report, as well as whether the controls operated effectively throughout the specified period to meet the applicable ISO 27001 control objectives. A Type II report includes not only the service organization’s management assertion and description of its system but also detailed results of testing of the service organization’s control over the specified period of time. ISO 27001 Surveillance Audits and Re-Assessment Audits The ISO 27001 Surveillance Audits and Re-Assessment Audits (every three years) will leverage to a large extent on the work done as part of the annual SOC2 Type II reporting. CREDENTIALS KPMG is a global leader in delivering Service Organization Control (SOC) reporting services. KPMG’s IT Attestation practice consists of a globally accredited network of partners and professional staff who provide a range of IT attestation services to help organizations satisfy their third-party assurance requirements. We have established a global accreditation process to help ensure consistency and quality in the delivery of attestation and assurance services including SOC1 and SOC 2 examinations and Agreed Upon Procedures. We have over 1,000 professionals fully trained in the SOC examination process through our global IT Attestation Instructor network. KPMG has a team of trained ISO 27001 lead auditors with extensive experience of performing certifications across all industry sectors. KPMG has a Certification Body that is accredited by the United Kingdom Accreditation Service (UKAS) to perform ISO 27001 certifications globally. contact Stephan Claes Dirk Timmerman Partner KPMG IT Advisory Executive Director KPMG IT Advisory T: +32 2 708 48 50 E: sclaes3@kpmg.com T: +32 2 708 43 59 E: dtimmerman@kpmg.com © 2013 KPMG Advisory, a Belgian civil CVBA/SCRL and a member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. Printed in Belgium.