ISO 27001 Certification
What is ISO 27001 certification?
ISO 27001 is the International Standard for Information Security Management. As with all ISO standards, it has been developed by a panel of experts from across the globe and provides a specification for the development of a ‘best practice’ information security management system (ISMS).
ISO 27001 certification involves an independent and accredited certification body (CB) assessing an organisation’s ISMS for compliance with the requirements of the Standard initially and on an annual basis.
By certifying to ISO 27001, organisations can demonstrate that they have a structured approach to the planning, implementation, and maintenance of an ISMS, capable of addressing both their current and ongoing information security and business needs.
How long does ISO 27001 certification last?
Where an ISO 27001 certificate is issued by an accredited CB (in the UK, the accreditation body is UKAS), it lasts three years, after which it will need to be renewed. Certification, however, is conditional on the effective ongoing operation of the in-scope ISMS.
The chosen CB will conduct annual continuous assessment visits (CAVs) and if the ISMS is not operating effectively, and timely action is not taken to address this, then a certification may be withdrawn.
What are the advantages and benefits of ISO 27001 certification?
Certifying to ISO 27001 formalises an organisation’s approach to information security management and will provide stakeholder assurance that a best practice approach is in place to safeguard all critical business information. Certification to ISO 27001 secures client confidence and is often a prerequisite to winning or retaining a client’s business.
An effective ISMS will also reduce the possibility of a security breach and the associated negative impacts, such as remediation costs and reputational damage. Equally, an effective ISMS will identify priorities so resources can be effectively allocated to ongoing security improvements.
The periodic external assessments involved in maintaining certification will also help an organisation ensures that it keeps focusing on continuous improvement.
How do I prepare for ISO 27001 certification?
Where in-house resource is available, URM can complement this, typically focusing its support on addressing key elements of the Standard such as risk assessment (consultancy and tool), policy development or staff training (online and classroom). Support will ensure avoiding pitfalls and common mistakes.
How to I achieve ISO 27001 certification
Once you have conducted your information security risk assessment and remediation activities and have fully implemented your ISMS, you can then engage a CB. You will need to be able to demonstrate that your ISMS is mature and fully operational and has been subject to a management review and internal audits (part of the continuous improvement cycle).
The actual certification process involves 2 stages. Stage 1 is a documentation review where your assessor will review your processes and policies to establish whether they are in line with the requirements of ISO 27001 and whether you are ready for a stage 2 audit.
The stage 2 audit (often referred to as the certification audit) is typically carried out 6-8 weeks later and involves a thorough on-site assessment to establish whether your ISMS fully conforms with ISO 27001 and your identified requirements.
The assessor will also be seeking evidence that your organisation is following its documented practices. If everything is in order, the assessor will recommend you for ISO 27001 certification.
How much does ISO 27001 certification cost?
This is dependent on a number of factors such as the size and complexity of the organisation or certification scope, the level of compliance already achieved and the internal resources available to support the project.
Organisations may look to secure certification using internal resources (with appropriate training, where required) or to engage expert consultancy support.
URM has supported over 200 successful certification projects and the level of support has varied greatly. Support requirements can be clarified by conducting a gap analysis or by addressing the key ‘risk assessment’ requirement of the Standard.
Can you get certified to ISO 27001 with URM?
As a leading ISO 27001 consultancy and training organisation, URM’s role is to assist you in developing an ISMS which not only meets the requirements of the Standard but that is tailored and appropriate to the current and future needs of your organisation and is not overly burdensome.
Provided its advice is taken, URM guarantees that any activities it undertakes and any deliverables it produces are fit for purpose in respect of achieving certification to ISO 27001.
To secure certification itself, organisations will need to engage a certification body (CB). URM works with all of the UK leading, UKAS accredited, CBs and can assist organisations in securing an appropriate quotation for ISO 27001 certification services.
MORE ABOUT URM CONSULTING AND HOW IT COULD
SUPPORT YOUR ISO 27001 JOURNEY
Since 2005, URM’s consultants have assisted over 200 organisations
achieve and maintain certification to ISO 27001.
We will ensure you never become a ‘slave to the Standard’ and
your ISMS is something which can easily be maintained and improved.
More about ISO 27001
Information Security Training
Our office is open 08:00 – 17:30 Monday to Friday.