International · International Organization for Standardization

ISO/IEC 27001, Information Security Management Systems

The international standard for an information security management system, and the certification most often requested by enterprise customers and procurement teams.

Who it applies to

Any organisation that wants a recognised, auditable statement that it manages information security as a system rather than as a collection of tools. It is voluntary, but in practice it is frequently mandatory: it is the certification enterprise procurement asks for by name.

What it requires

  • A defined scope, stating which parts of the business and which systems the management system covers
  • A risk assessment methodology that is applied consistently, and risk treatment decisions that are recorded with their rationale
  • A Statement of Applicability justifying every Annex A control that is included and, more importantly, every one that is excluded
  • Documented policies, assigned ownership, and evidence that controls operate rather than merely exist
  • Internal audit and management review, both performed before the certification body arrives
  • Demonstrated continual improvement, which is what surveillance audits actually test

What preparing for it involves

The work divides into scoping, gap closure and evidence. Scoping is where most programmes are won or lost: a scope drawn too wide creates years of work, and one drawn too narrow fails to satisfy the customer who asked for the certificate. Gap closure addresses what the assessment found. Evidence is the part organisations underestimate, because an auditor tests whether a control operated throughout the period, not whether a policy exists today.

How it concludes

A certificate issued by an accredited certification body, typically valid for three years with annual surveillance audits. The certificate is issued by the certification body and not by us.

SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.

Cross-framework reuse

Control mappings exist between this framework and others in the library, so evidence gathered here may support work elsewhere. Mappings are published as draft, and a mapping shows a relationship rather than satisfied coverage. An auditor decides whether the evidence answers the requirement.