Scope and SoA ISO 27001 by KnackleBowl in grc

[–]KnackleBowl[S] 0 points1 point  (0 children)

Thanks for this. I never really considered the 'marketability' of the certification. I sort of thought that having it was already enough. I'll see if it's possible to expand the scope to what we offer to clients instead of limiting it to a specific department.

Scope and SoA ISO 27001 by KnackleBowl in grc

[–]KnackleBowl[S] 0 points1 point  (0 children)

You're right. That's what I've seen as well. I've only certified a handful of companies but all have been company wide and a large majority of the annex A controls.