AQC Group regional partnerIraq

Certification for IT companies

IT companies are asked, often in a tender or a security questionnaire, how they protect client data and how they run their services. Two standards answer those questions: ISO/IEC 27001 for information security and ISO/IEC 20000-1 for IT service management. ISO 9001 can sit beside them.

People working at rows of monitors in an open office

01What we ask first

The questions we put to every it companies enquiry, with the answer an auditor would give.

Q01

How do you manage information security and client data protection?

An auditor starts with what information you hold and what could go wrong with it. They then look at how risks are assessed, which controls you chose and why, how access is given and reviewed, how suppliers and cloud providers are controlled, how backups are tested and how staff are made aware of their duties.

ISO/IEC 27001 addresses this. Having it in place means a written risk assessment and treatment plan, a statement of which controls apply and why, incidents that are recorded and reviewed, and management that looks at the results. Certification shows that the system is in place and working. It does not promise that no breach will happen. Check the legal requirements on data protection that apply to you.

Addressed byISO/IEC 27001

Q02

Are your clients asking for cybersecurity or data security compliance?

Clients put these requests into tenders and supplier security questionnaires, and a certificate to ISO/IEC 27001 is a common answer to them. Read what the client actually asks for. Some want a certificate, some want specific controls, and some want to audit you themselves.

A certificate has a scope, which states the services, locations and systems it covers. Check that the scope matches what the client is buying from you. A certificate that covers only your head office may not satisfy a client whose data sits in a data centre outside it.

Addressed byISO/IEC 27001

Q03

Do you have any IT service management framework implemented?

ITIL is a framework of good practice. It is widely used, but an organization cannot be certified to it. ISO/IEC 20000-1 is the standard for IT service management that an organization can be audited and certified against, and a company that already follows ITIL practices has a head start on it.

Having it in place means the services you offer are defined, agreed service levels are measured, incidents and requests are recorded and resolved, changes are controlled, and suppliers behind your services are managed. The auditor samples real tickets, changes and reports to see that this happens.

Addressed byISO/IEC 20000-1

Q04

Does a certificate cover the whole company or only part of it?

Only what you put in the scope. A company can certify one service, one team, one site or the whole organization, and the certificate names exactly what is covered. A narrow scope is allowed, but it has to be honest and it has to match how you describe yourself to clients.

For ISO/IEC 27001 the scope is set around the information and systems you manage. For ISO/IEC 20000-1 it is set around the services you deliver to customers. Settle the scope before the quotation, because it decides the size of the audit. We can talk it through with you.

Addressed byISO/IEC 27001ISO/IEC 20000-1

Tell us what your customer is asking for.

We will tell you which standard it means, what the audit involves and what affects the time it takes.