Skip to content

Standards

Last checked on

Standards shows the standard your workspace adopted and all its requirements. You decide per requirement whether it applies and how far you have got, establish the Statement of Applicability and export everything your auditor needs.

Why this protects your organisation

Not every requirement in a standard fits every organisation. A software company without its own server room handles physical security differently from one with a data centre. An auditor wants to know which requirements you consider applicable, why you excluded the others, and what you have actually put in place. If you cannot explain that, you cannot defend your choices in an audit or to a customer. In ISO 27001 this is the Statement of Applicability (clause 6.1.3): your own reasoned choice per control, which the auditor checks against your risks.

Steps

  1. Open Standards in the Prove group and click Edit on the row of your standard.
  2. Describe the Scope, or choose the Established scope statement you set on the Scope page. Save.
  3. In the requirements table, click Assess on a requirement, choose Applicable or Not applicable, write a Justification and set the Implementation status.
  4. Repeat until the Assessed column on the overview shows every requirement.
  5. Click Establish Statement of Applicability at the top of the page. The new version appears under Statement of Applicability, where you can Download PDF.
  6. Before an audit, click Export for the auditor under Exports for the auditor, choose the period and wait for the email with the link.

The overview lists each standard with its Version, Scope, the number of requirements Assessed, the AI estimate of readiness and the date it was Adopted on. The catalogue currently holds the full requirement set of ISO 27001:2022, including the controls of Annex A, written in Trustbird's own words in English and Dutch.

The requirements table

Requirements are shown as a tree: sub-requirements sit indented under their parent. For each one you see the Code, the Requirement, the Applicability, the Implementation status, your Justification and the Measures linked to it. When you click Assess, the form often shows a question in plain language and what an auditor usually wants to see. Your justification is your own reasoning; Trustbird never fills it in for you.

The column AI opinion on the evidence shows what the AI thinks of the current evidence for that requirement. Hover over it to read why. It is a suggestion next to your own decision, never instead of it.

Statement of Applicability and exports

Each established version is fixed. Later decisions go into the next version, so you can always show an auditor what applied when. Under Exports for the auditor you put together one ZIP file with a summary, the established Statement of Applicability, the evidence files with an index, the AI judgments and the audit trail of the period you chose. The download link is available for a limited time and only works for members of the workspace.

Linking measures and other versions

You link measures and evidence to requirements from the Measures and Evidence screens; the linked measures then show up here. If a newer published version of your standard becomes available, Switch version creates a new adoption on it and carries over decisions for requirements the catalogue marks as equal. Related requirements appears only when your workspace has adopted a second standard with requirements the catalogue links to this one.

If it does not work

I cannot add a standard

There is no button to add one on this screen. The standard is chosen when the workspace is created, and Trustbird sets up all its requirements for you.

I do not see the button Establish Statement of Applicability

Establishing is for the owner and members, and for an advisor with edit rights for the module Standards and certification. Ask the workspace owner if you need it.

My Statement of Applicability still shows requirements as not yet assessed

Requirements you have not assessed go into the established version as they are. The confirmation tells you how many. Assess them and establish a new version; the earlier versions stay available.

The column AI estimate of readiness says Not yet estimated

The estimate only appears once requirements are marked applicable, linked to measures and those measures have evidence the AI has assessed. It is a suggestion and never changes the status you set.

Screens this is about

  • Standards

Read next