I am starting out contracting under a Ltd company and I am the only employee. I am filling in a Due Diligence form and they ask if I do not hold ISO27001 Information Security Certification then do I have a documented Information Security Policy, has anyone else had this question and how have they dealt with it? I am providing project management services and I guess as a contractor I will have to use my own laptop.
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
IT Security Policy
Collapse
X
-
-
You can review the Cyber Essentials questionnaire and see how much you are aware of/conform to its requirements https://www.cyberaware.gov.uk/cyberessentials
This might serve as a baseline Information security policy for your business and if needed, you can get your business certified too.
(sufficient for a small business I think, but not quite ISO27001) -
-
I guess the jobsworth have put you on their portfolio to undergo the 3rd party due diligence assurance which is aligned to ISO27001. Call them up and let them know you are a one man company and not in scope for the process.Comment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Top 5 contractor compliance challenges, as 2025-26 nears Oct 3 08:53
- Joint and Several Liability ‘won’t retire HMRC's naughty list’ Oct 2 05:28
- What contractors can take from the Industria Umbrella Ltd case Sep 30 23:05
- Is ‘Open To Work’ on LinkedIn due an IR35 dropdown menu? Sep 30 05:57
- IR35: Control — updated for 2025-26 Sep 28 21:28
- Can a WhatsApp message really be a contract? Sep 25 20:17
- Can a WhatsApp message really be a contract? Sep 25 08:17
- ‘Subdued’ IT contractor jobs market took third tumble in a row in August Sep 25 08:07
- Are CVs medieval or just being misused? Sep 24 05:05
- Are CVs medieval or just being misused? Sep 23 21:05
Comment