Our team is initiating our pursuant of ISO 27001.  Any general guidance from those who have recently been through the process and received their certification?

587 viewscircle icon3 Comments
Sort by:
Head, Software Engineering, Cloud and Digital Transformation16 hours ago

1. Go through each controls of ISO 27001. Identify a person who can lead this effort. Have the person conduct internal audit against all the controls, document the gaps and find a way to fill the gap. 
2. For each control, have the policy or guidelines documented, internally reviewed, approved and published.  Each document should have last review date. And then collect evidence of use to show the auditor.
3. Do not volunteer additional information other than what has been asked by auditor :-). 

Hope this helps. Happy to help more if you need. All the best for audit and certification.

Director of IT2 months ago

Before pursuing ISO 27001 certification, the company should first understand the standard and gain executive buy-in to secure resources and support. The next step is defining the ISMS scope, followed by conducting a gap analysis to assess current security posture. A project plan should be created, and a risk assessment carried out to identify and treat risks, culminating in a Statement of Applicability.
Required policies and procedures must be documented, and the ISMS implemented across their company, supported by staff training and awareness. Internal audits and a management review help verify effectiveness before selecting a certification body. An optional readiness review may be conducted prior to the formal certification audit, which is performed in two stages: a documentation review and a full audit of the ISMS.
Key points to call out are:
Ensure staff understand and support the initiative, and that top management have bought into the initiative.
Be prepared for the additional documentation burden, ISO27001 is documentation-heavy.
Be ready for the fact that certification requires continuous improvement and re-certification every 3 years, including annual surveillance audits.
If the business holds other standards then all the standards will need to be integrated (e.g., ISO9001) into an integrated management system.

Lightbulb on1 circle icon1 Reply
no title16 hours ago

Thank you for your feedback Alex.

Content you might like

Whitepapers17%

Ebooks40%

Report17%

Video17%

Podcast6%

Articles2%

View Results

Pay increases / hiring bonus44%

Paying more Overtime61%

Sharing employees across locations and regions36%

Going to agency more often9%

View Results