Yes - Clause 9.2 of the Standard makes this requirement explicit.  Remember, you must audit to assess whether your ISMS is meeting your own organisational requirements as well as the requirements of the Standard and that it is effectively implemented and maintained.

No items found.
"
We've been using URM for our PCI DSS assessments for the last 5 years and we are pleased with their service. The assessment is always completed promptly, the price is competitive, and communication is great. We'll keep using them and are happy to recommend URM to anyone.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.