ISO 27001: the steps to certification

The steps to ISO 27001 certification: scope, risk assessment, controls, internal audit and the two stages of the certification audit.

ISO/IEC 27001 certification is not an exam you sit once. It is evidence that the organization has an information security management system (ISMS) that works and improves. The road there has well-known steps.

Preparation

  • Define the scope: which services, offices and systems the ISMS covers.
  • Secure management support, with roles, objectives and resources.
  • Carry out the risk assessment and decide how each risk will be treated.
  • Prepare the Statement of Applicability: which Annex A controls you apply and why.

Implementation

Put the controls in place and write the policies and procedures you really need. Train staff and start collecting evidence: auditors do not assess what you have written, but whether you follow it.

Internal checks

  • The internal audit checks whether the system works as described.
  • The management review assesses the results and decides on improvements.
  • Nonconformities found are handled with corrective actions.

The certification audit

It is carried out by an accredited certification body in two stages. In stage one the auditor reviews the documentation and readiness. In stage two the auditor checks in practice whether the controls are applied.

After certification

The certificate is valid for three years. During that time there are surveillance audits every year and a recertification audit at the end. The system has to stay alive, not be prepared only before the audit.

Related serviceISO 27001 Implementation and AuditISMS design, risk management, Annex A controls and certification support.Learn more

Let's talk about your next engagement.

Tell us about your engagement — we typically respond within one business day.

WhatsApp +355 69 522 4573