article thumbnail

ISO 27001 Certification Requirements & Standards

Reciprocity

Within the ISO 27001 family, there are many other vital documents. They include: ISO 27005: Information security risk management these standard guides companies that are maturing their ISMS and controls programs. Third, create a project plan and a project risk register. Perform a Gap Analysis. Analyzing risks.

Audit 52
article thumbnail

Audit Checklist for SOC 2

Reciprocity

A SOC 2 Type 1 report attests to the design and documentation of a service organization’s internal controls and procedures as of a specific date. Perform a SOC 2 Gap Analysis. Once you’ve completed your audit preparation, you should perform a gap analysis.

Audit 52