
Episode #65
ISO 27001 vs SOC 2: What’s the Difference? with Sam Mather and Rob Hall | Part 1
ISO 27001 and SOC 2 are two of the most in-demand information security frameworks, but how do they actually compare, and how do you know which one your organisation needs? In this episode of Exploring Standards, host Jess is joined by Sam from Assent Risk Management and Rob Hall from Tempo Audits to break down the similarities and differences between these two frameworks. They cover the shared risk-based approach and overlapping controls both frameworks require, the key methodology differences (ISO 27001's management-system approach vs. SOC 2's focus on control effectiveness), and why customers request one, the other, or both, from industry mandates and customer location to commercial and cost considerations like SOC 2's trust services criteria. This is part one of a two-part series adapted from a live Assent Risk Management webinar. Stay tuned for part two, where the conversation continues. Contact Assent: Website: www.assent1.com Email: desk@assent1.com Connect with Assent: LinkedIn: https://www.linkedin.com/company/associate-enterprises-ltd-t-a-assent/ Facebook: https://www.facebook.com/assentuk Youtube: https://www.youtube.com/channel/UCWw6ny-YyfkxdGm7ig4yFoQ Instagram: @assentriskmanagement Contact Rob: www.tempoaudits.com https://www.linkedin.com/in/robjshall/

