Hot take: ISO standards do not meaningfully matter to me, because an extremely impoverished, unbanked person cannot freely access their contents from a smartphone or library computer.

Therefore, I go out of my way to avoid referring to them or relying on them in anyway.

@soatok ISO standards are behind a fuckin paywall?

jesus christ

@matildalove @soatok
ISO: "We created global standards for everyone to follow"
Everyone: "Can we see them?"
ISO: "No"

@aires @matildalove @soatok

They're industrial standards. There's an underlying assumption that you're not going to be able to make use of them without massive amounts of capital equipment, and a further assumption that if you're not able to make use of them, they're probably not very interesting or relevant to you.

Maybe those assumptions are flawed. But they're at least not surprising.

@publius @aires @matildalove @soatok
As a comsumer how do I view the standard so I can check a product complies?
@emilion @geoffl @publius @aires @matildalove @soatok That cert isn't worth the paper it's written on without the SOA and rigorous verification.
@itisiboller @geoffl @publius @aires @matildalove @soatok I strongly disagree. The certificate is issued only after an external compliance audit. How can an independent validation be worthless? An SOA is available upon request.
@emilion @geoffl @publius @aires @matildalove @soatok Yes, but the scope could have been for the large corps canteen and they'd still be able to claim an ISO27001 cert in which case the cert is effectively useless w/o thoroughly reading the SOA.
@itisiboller @geoffl @publius @aires @matildalove @soatok The scope is listed on the cert. No external auditor would certify a canteen under ISO 27001.
I think you are trying to say that ISO cert is not a guarantee that everything is top notch. If so, I agree.

@emilion @itisiboller @geoffl @publius @aires @matildalove @soatok eh? It isn't up to the auditor to say if the scope is not acceptable. If the business has defined the scope and applicable controls (via a risk management process), then the auditor audits against that. This is why seeing the SoA is important.

The scope is on the cert, but not the controls that have been selected.

Now, the auditor could raise a non-conformity against the risk management process if it was piss-poor.

@puck @itisiboller @geoffl @publius @aires @matildalove @soatok "ISO 27001 Statements of Applicability (SOAs)—a confidential compliance report type—are available upon request."

https://www.ibm.com/cloud/compliance/iso-27001

What is ISO/IEC 27001? | IBM

ISO 27001 is the leading globally recognized information security standard, providing a systematic, structured and risk-based approach for managing and protecting sensitive information assets.

@emilion @itisiboller @geoffl @publius @aires @matildalove @soatok Some companies refuse to make their SoA available.
@puck That is a huge red flag. That org has something to hide.
Certificates - Hetzner Docs