I’ve been asked by management to give an opinion as to whether we need to pursue an ISO-27001 certification. This is pretty difficult without the ISO-17799 controls. They don’t want to spend the money on the ISO-17799 tool kit unless it makes sense to pursue it at our current location but I can’t give them an answer without the list of controls.
Does anybody know where I can get a list of the ISO-17799 controls? If it makes sense to pursue the certification I will purchase the kit.
Thanks,
David Hegner