Skip to main content

What is the difference between questions MAIN 1.1 and MAIN 1.2 in Appendix A of the RSP Handbook?

Though MAIN 1.1 references ISO 27001, and ISO 27001 describes requirements for an information security management system which is the subject of MAIN 1.2, these are not duplicative questions.

MAIN 1.1 is a Yes or No question asking for attestation of a publicly verifiable, third-party security certification. One such certification may be acquired through ISO 27001 compliance, but there are others.

MAIN 1.2 requires a description of the information security management system, whether or not it is compliant with ISO 27001.