{"id":426445,"date":"2024-10-20T07:02:05","date_gmt":"2024-10-20T07:02:05","guid":{"rendered":"https:\/\/pdfstandards.shop\/product\/uncategorized\/bsi-23-30470501-dc\/"},"modified":"2024-10-26T13:18:00","modified_gmt":"2024-10-26T13:18:00","slug":"bsi-23-30470501-dc","status":"publish","type":"product","link":"https:\/\/pdfstandards.shop\/product\/publishers\/bsi\/bsi-23-30470501-dc\/","title":{"rendered":"BSI 23\/30470501 DC"},"content":{"rendered":"
PDF Pages<\/th>\n | PDF Title<\/th>\n<\/tr>\n | ||||||
---|---|---|---|---|---|---|---|
7<\/td>\n | Foreword <\/td>\n<\/tr>\n | ||||||
9<\/td>\n | Introduction <\/td>\n<\/tr>\n | ||||||
11<\/td>\n | 1 Scope 2 Normative references 3 Terms and definitions <\/td>\n<\/tr>\n | ||||||
14<\/td>\n | 4 Principles 5 General requirements 5.1 Legal and contractual matters <\/td>\n<\/tr>\n | ||||||
15<\/td>\n | 5.2 Management of impartiality 5.2.1 General 5.2.2 Conflicts of interest 5.3 Liability and financing 6 Structural requirements 7 Resource requirements 7.1 Competence of personnel 7.1.1 General 7.1.2 General considerations <\/td>\n<\/tr>\n | ||||||
16<\/td>\n | 7.1.3 Determination of competence criteria <\/td>\n<\/tr>\n | ||||||
18<\/td>\n | 7.2 Personnel involved in the certification activities 7.2.1 General <\/td>\n<\/tr>\n | ||||||
19<\/td>\n | 7.2.2 Demonstration of auditor knowledge and experience 7.3 Use of individual external auditors and external technical experts 7.4 Personnel records 7.5 Outsourcing <\/td>\n<\/tr>\n | ||||||
20<\/td>\n | 8 Information requirements 8.1 Public information 8.2 Certification documents 8.2.1 General 8.2.2 ISMS Certification documents 8.2.3 ISMS Certification documents and sector specific standards 8.2.4 Interested party requirements <\/td>\n<\/tr>\n | ||||||
21<\/td>\n | 8.3 Reference to certification and use of marks 8.4 Confidentiality 8.4.1 General 8.4.2 Access to organizational records 8.5 Information exchange between a certification body and its clients 9 Process requirements 9.1 Pre-certification activities 9.1.1 Application <\/td>\n<\/tr>\n | ||||||
22<\/td>\n | 9.1.2 Application review 9.1.3 Audit programme <\/td>\n<\/tr>\n | ||||||
23<\/td>\n | 9.1.4 Determining audit time 9.1.5 Multi-site sampling <\/td>\n<\/tr>\n | ||||||
24<\/td>\n | 9.1.6 Multiple management systems <\/td>\n<\/tr>\n | ||||||
25<\/td>\n | 9.2 Planning audits 9.2.1 Determining audit objectives, scope and criteria 9.2.2 Audit team selection and assignments 9.2.3 Audit plan <\/td>\n<\/tr>\n | ||||||
26<\/td>\n | 9.3 Initial certification 9.3.1 General 9.3.2 Initial certification audit <\/td>\n<\/tr>\n | ||||||
27<\/td>\n | 9.4 Conducting audits 9.4.1 General 9.4.2 Specific elements of the ISMS audit 9.4.3 Audit report <\/td>\n<\/tr>\n | ||||||
28<\/td>\n | 9.5 Certification decision 9.5.1 General 9.5.2 Certification decision 9.6 Maintaining certification 9.6.1 General 9.6.2 Surveillance activities <\/td>\n<\/tr>\n | ||||||
29<\/td>\n | 9.6.3 Re-certification 9.6.4 Special audits 9.6.5 Suspending, withdrawing or reducing the scope of certification <\/td>\n<\/tr>\n | ||||||
30<\/td>\n | 9.7 Appeals 9.8 Complaints 9.8.1 General 9.8.2 Complaints 9.9 Client records 10 Management system requirements for certification bodies 10.1 Options 10.1.1 General 10.1.2 ISMS implementation 10.2 Option A: General management system requirements 10.3 Option B: Management system requirements in accordance with ISO\u20ac9001 <\/td>\n<\/tr>\n | ||||||
31<\/td>\n | Annex\u20acA (normative) Knowledge and skills for ISMS auditing and certification <\/td>\n<\/tr>\n | ||||||
32<\/td>\n | Annex\u20acB (normative) Audit time <\/td>\n<\/tr>\n | ||||||
38<\/td>\n | Annex\u20acC (informative) Methods for audit time calculations <\/td>\n<\/tr>\n | ||||||
42<\/td>\n | Annex\u20acD (informative) Guidance for review of implemented ISO\/IEC\u20ac27001:2022, Annex\u20acA controls <\/td>\n<\/tr>\n | ||||||
68<\/td>\n | Annex\u20acE (informative) Requirements and limits for certifications according to sector-specific standards <\/td>\n<\/tr>\n | ||||||
69<\/td>\n | Annex\u20acF (normative) Requirements for certification including sector-specific standards <\/td>\n<\/tr>\n | ||||||
70<\/td>\n | Annex\u20acG (informative) Further competence considerations <\/td>\n<\/tr>\n | ||||||
72<\/td>\n | Bibliography <\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":" BS EN ISO\/IEC 27006-1.2. Information technology, cybersecurity and privacy protection. Requirements for bodies providing audit and certification of information security management systems – Part 1. General<\/b><\/p>\n |