ISO/IEC 27001 certification concerns an information security management system within a defined scope. To understand the claim, identify the organization, information-related activities and boundaries being assessed. A certificate should not be read as a promise that every system is invulnerable.
The official ISO catalogue identifies the 2022 edition and related information. Assessment planning also needs to take account of applicable amendments and programme arrangements.
Scope is the first important decision
An organization may provide several services, use several locations and depend on external infrastructure. The ISMS scope needs to explain what is included and how relevant interfaces are handled. A product brand alone may not identify the legal or operational boundary.
For example, a hosted application can involve the applicant’s development team, a cloud platform and an external support provider. Describe the roles rather than assuming that one party’s certificate covers the whole chain.
Risk assessment and treatment need context
The organization should be able to explain the information and activities it is considering, how it makes risk-related decisions and how those decisions connect to controls. A copied risk list may omit the features that matter most to the actual service.
Keep the reasoning understandable to the people responsible. If a decision depends on a supplier arrangement or a technical assumption, identify that dependency so it can be reviewed when circumstances change.
Understand the Statement of Applicability
The Statement of Applicability is important information within an ISMS assessment. It should be consistent with the organization’s applicable requirements and control decisions. Treat it as part of the system’s reasoning, not simply a checklist to complete immediately before an audit.
The standard and applicable guidance provide the detailed requirements. This article does not reproduce a full control catalogue or prescribe the same controls for every organization.
What evidence may be useful?
Depending on scope, an applicant may need to explain how access, changes, incidents, supplier relationships and evaluation are handled. Operational records should connect with the described process. If a process is outsourced, the applicant still needs to explain its own responsibilities and relevant interfaces.
Arrange appropriate access to sensitive information before assessment. Do not disclose customer secrets, credentials or personal records through an unsecured application email merely to demonstrate readiness.
Distinguish certification from other assurance
A penetration test, a product security review, a SOC report and an ISMS certificate serve different purposes. A customer may require more than one type of evidence. Ask what the customer needs and avoid describing one mechanism as a universal replacement for the others.
Prepare a focused enquiry
List the services, organizational functions, locations and major supplier dependencies in scope. Include existing certification and any customer acceptance conditions. See ISO/IEC 27001 certification and contact EQRM to discuss the proposed assessment.
Map one information-service dependency
Choose a service in the intended ISMS scope and identify the information it uses, the systems supporting it, the suppliers involved and the responsibilities retained by your organization. Explain how changes and incidents move across those boundaries. Use that map to check whether the risk treatment, supplier arrangements and operating evidence describe the same service.
Quick answers
Is ISO/IEC 27001 a product security guarantee?
No. It concerns the information security management system within scope. It does not mean every product is invulnerable or every technical test has been passed.
Does a cloud provider’s certificate cover its customer automatically?
No. Identify the provider’s scope and the customer’s responsibilities. Using a certified supplier does not automatically certify the customer’s system.