Skip to content

Prove: what you show here and why

Last checked on

The Prove group is where you show others how you are doing: your standards and Statement of Applicability, your certificates and their audit cycle, and the trust page where customers see what you choose to share.

Why this protects your organisation

Customers, prospects and auditors do not take your word for it. They want to see which standard you follow, which parts apply to you, whether your certificate is still valid and how you handle their data. If that information lives in scattered files and inboxes, every security questionnaire and every audit costs days. This group keeps it in one place, so you can show it quickly and consistently, and so the evidence an auditor asks for under ISO 27001 is ready when the audit starts.

Steps

  1. Open Standards and assess, per requirement, whether it applies to you and how far you have got.
  2. Establish the Statement of Applicability once the assessments are complete.
  3. Record your certificate under Certificates. Its audit cycle then appears under External audits.
  4. Record each external audit and its findings once it has taken place.
  5. Add policy summaries and security practices under Trust page content, and have the owner establish them.
  6. Choose documents customers may request under Documents on request, then have the owner switch the trust page on.

The screens in this group build on what you record elsewhere in Trustbird. Your measures, evidence and established documents come together here in a form you can show to someone outside the organisation.

  • Standards: the standard your workspace adopted, with its scope and every requirement. You decide per requirement whether it applies and why, establish the Statement of Applicability and put together an export for your auditor.
  • Certificates: the certificates you hold, with the certifying body, the certificate number and how long they are valid. Each certificate also has a badge you can share.
  • External audits: the audit cycle of each certificate, from the initial audit to recertification, with what the auditor found and by when you need to respond.
  • Trust page: switch your public trust page on and choose what appears at the top of it.
  • Trust page content: short summaries of your policies and descriptions of how you work, written for customers.
  • Documents on request: established documents customers may request after accepting an NDA.
  • Document requests: the requests that come in, where you approve or reject each one and see who received which version.

Trustbird does not verify certificates and does not certify anything. What appears here is what your organisation recorded and established itself.

If it does not work

I cannot change anything in this group

Advisors can only read here, unless the workspace owner gives them edit rights for the module Standards and certification. Some actions, such as switching the trust page on or establishing its content, are reserved for the owner.

I do not see Document requests in the menu

Only the owner and members of the workspace see requests for documents. Advisors do not.

Read next