@emilion @geoffl @publius @aires @matildalove @soatok Here a scope we recently reviewed (company name removed to protect the guilty) "
Planning, building, delivering and running full-scope outsourcing services, end-to-end
support, business solutions, consulting services and security services".
Still without the SOA this does not give me ANY evidence that they are good - So much so that we've often joked that it's faster and easier to become DA in a pentest of a company with ISO27k than one without (based on 10's of companies so not a large enough sample size).
So no what I'm saying is exactly that without the SOA it is not the paper worth it is written on, and even with the SOA all you know is that they have a good ISMS (which I support) but not necessarily does any RealSecurity™.
For the record just got ISO27k certified for a part of the org I currently work for and that does not change my mind - Time spent on that certification with "renowned" large international orgs would have given soooo much more protection, detection, and response spent elsewhere.