ISO/IEC 27001 certification is not an exam you sit once. It is evidence that the organization has an information security management system (ISMS) that works and improves. The road there has well-known steps.
Preparation
- Define the scope: which services, offices and systems the ISMS covers.
- Secure management support, with roles, objectives and resources.
- Carry out the risk assessment and decide how each risk will be treated.
- Prepare the Statement of Applicability: which Annex A controls you apply and why.
Implementation
Put the controls in place and write the policies and procedures you really need. Train staff and start collecting evidence: auditors do not assess what you have written, but whether you follow it.
Internal checks
- The internal audit checks whether the system works as described.
- The management review assesses the results and decides on improvements.
- Nonconformities found are handled with corrective actions.
The certification audit
It is carried out by an accredited certification body in two stages. In stage one the auditor reviews the documentation and readiness. In stage two the auditor checks in practice whether the controls are applied.
After certification
The certificate is valid for three years. During that time there are surveillance audits every year and a recertification audit at the end. The system has to stay alive, not be prepared only before the audit.
