INFORMATION SECURITY
ISO/IEC 27001 certification
An information security management system connects information risks with treatment decisions, responsibilities and review. Define the services, information, people and supplier interfaces in scope so customers can understand what the certification covers.
AT A GLANCE
STANDARD REFERENCE
ISO/IEC 27001:2022
Information Security Management System
ASSESSMENT SUBJECT
Your management system
Certification applies to the agreed organizational scope.
Your application identifies the edition, activities and sites to be assessed.
UNDERSTAND THE STANDARD
What is ISO/IEC 27001 certification?
ISO/IEC 27001 specifies requirements for an information security management system, often called an ISMS. It addresses the organizational management of information-security risks within defined boundaries. Certification is not a guarantee that a breach will never happen or a technical endorsement of every system the organization uses.
Clarify which information and services the organization intends to protect within the ISMS. A hosted application, an internal support operation and a group-wide business function can have different boundaries. Identify who owns the decisions and where customers, cloud providers and other suppliers share responsibilities.
START WITH THE BOUNDARY
Make the scope clear.
Describe the organizational units, services, information, systems and locations in scope, including relevant interfaces. Explain remote personnel and outsourced infrastructure. Do not assume that a cloud provider’s certificate automatically covers the customer organization’s own processes.
FROM INTENT TO EVIDENCE
Show how your system works.
These are examples of relevant information, not a universal list of mandatory documents. The evidence depends on your activities and applicable requirements.
01
A documented account of the ISMS boundaries and relevant interfaces.
02
Risk assessment and treatment decisions tied to the organization’s context.
03
The Statement of Applicability and the rationale associated with controls.
04
Operational records showing how access, incidents, changes and evaluation are handled where relevant.
A PRACTICAL EXAMPLE
Put the scope into context.
A software provider may rely on a third-party cloud platform while retaining responsibility for user access and application changes. An enquiry should distinguish what the supplier manages from what the applicant manages. This helps avoid a scope description that appears broad but leaves key responsibilities unclear.
Use this example to prepare your own scope and evidence.
HOW CERTIFICATION WORKS
A clear route from enquiry to decision.
01
Scope & application
Describe the activities, sites and standard you want assessed.
02
Assessment planning
Agree arrangements based on the application and programme.
03
Audit & response
Demonstrate the system and address findings with evidence.
04
Decision & review
Certification follows a decision, with continuing assessment as applicable.
An application or completed audit does not guarantee certification.
EDITION & APPLICATION
Confirm the right basis for assessment.
The planning reference is ISO/IEC 27001:2022. Applicable amendments, transition arrangements and the edition for your application must be confirmed before assessment is agreed.
Check the official ISO publication information. Use the official publication record to check the edition and related amendments.
CONNECTED MANAGEMENT NEEDS
Considering several standards?
Shared processes can support a coordinated system. Explain the common boundaries and the differences.
FREQUENTLY ASKED QUESTIONS
ISO/IEC 27001: frequently asked questions
Clear answers before you take the next step.
Is ISO/IEC 27001 certification the same as penetration testing?
No. A penetration test is a technical activity with its own scope and methods. An ISMS assessment addresses the management system. Relevant technical evidence may inform the system, but the two should not be represented as equivalent services.
Is ISO/IEC 27001 certification the same as a penetration test?
No. A penetration test examines a defined technical target. Management system certification concerns how information security is governed and managed within the organizational scope.
Can cloud services be included in the scope?
Describe the services, information, systems and supplier interfaces involved. Explain which responsibilities sit with your organization and which sit with the cloud provider.
Can ISO/IEC 27001 be assessed with other standards?
Other systems may share responsibilities or processes with ISO/IEC 27001, but each retains its own requirements. Explain the intended standards, sites and boundaries when discussing an integrated assessment.
What affects the cost and timing of ISO/IEC 27001 certification?
The scope, activities, personnel, locations and applicable programme determine the proposed assessment work. Readiness and responses to findings also affect timing. Request a quotation based on your actual organization.
START WITH YOUR ORGANIZATION
Discuss ISO/IEC 27001 with EQRM.
Tell us your activities, locations and ISO/IEC 27001 requirements. We’ll review availability and the scope of the proposed engagement.