Yes - Clause 9.2 of the Standard makes this requirement explicit.  Remember, you must audit to assess whether your ISMS is meeting your own organisational requirements as well as the requirements of the Standard and that it is effectively implemented and maintained.

No items found.
"
On our path of growing our business, we have found in URM a very capable and knowledgeable consultancy firm to guide and structure our processes towards SOC 2 compliance. The consultancy by URM played an essential role in building our competences and expanding the compliance framework for our SaaS based propositions.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.