ISO/IEC 27001:2022
Governs how client data is classified, stored, accessed and disposed of, and how security risk is assessed on every engagement.
What it governs in practice
- Client information is classified on receipt, and the classification determines who may access it, where it may be stored and how long it is retained.
- Access to engagement systems is granted by role and withdrawn when a person leaves the engagement, not when they leave the firm.
- Every engagement carries a documented risk assessment covering the data it touches, with treatment decisions recorded and reviewed.
- Security incidents follow a defined reporting, containment and notification path, including notification to the client.