Q01
How do you manage information security and client data protection?
An auditor starts with what information you hold and what could go wrong with it. They then look at how risks are assessed, which controls you chose and why, how access is given and reviewed, how suppliers and cloud providers are controlled, how backups are tested and how staff are made aware of their duties.
ISO/IEC 27001 addresses this. Having it in place means a written risk assessment and treatment plan, a statement of which controls apply and why, incidents that are recorded and reviewed, and management that looks at the results. Certification shows that the system is in place and working. It does not promise that no breach will happen. Check the legal requirements on data protection that apply to you.
Addressed byISO/IEC 27001
