What is ISO 27001 certification?
Increasing pressure from regulators, clients and the public for better assurances about the way in which organisations manage confidential and sensitive data has resulted in rapid growth of certification to ISO 27001 – especially in the UK (which ranks second in the world).
ISO 27001 is the international standard that lays out the specifications for implementing an ISMS (information security management system). An ISMS can be audited by an independent CB (certification body) as a way to assess whether it conforms to the requirements of the Standard.
Purchase your copy of the standard today >>
How long does ISO 27001 certification last?
Once certification is granted it is valid for three years, although the ISMS will need to be managed and maintained throughout that period. Auditors from the CB will continue to conduct surveillance visits every year while the certification is valid.
Advantages of ISO 27001 certification
Although many organisations use ISO 27001 as a framework for information security best practice, organisations may prefer not to get certified at all, or postpone the certification process. There are, however, numerous benefits to achieving certification. Many organisations opt for certification because of client or contractual requirements.
Explore the benefits of achieving ISO 27001 certification
Learn more about the benefits of ISO 27001 certification in our free green paper: Information Security & ISO 27001: An introduction
The steps to ISO 27001 certification
Organisations that have identified that they need ISO 27001 certification often come to us for advice about what to do first. There are a number of options, depending on your budget, timeframe and resource availability.
We’ve outlined the basic recommended routes in a helpful PDF guide - download your copy today >>
The ISO 27001 certification process
Once you are ready for certification, you will need to engage the services of an independent, accredited CB. These CBs have been assessed by the relevant national authority based on their competence, impartiality and performance capability through a rigorous assessment process.
The certification process consists of two stages and is conducted by a qualified auditor.
The auditor will review your documentation to check that the ISMS has been developed in accordance with the Standard. You will be expected to present evidence of all key aspects of the ISMS, but how much depends on the CB’s requirements.
If you pass the first stage, the auditor will conduct a more thorough assessment. This will involve reviewing the actual activities that support the development of the ISMS. The auditor will analyse your policies and procedures in greater depth, and review how the ISMS works in practice, with an on-site investigation. The auditor will also interview key members of staff to verify that all activities are undertaken in accordance with the specifications of ISO 27001.
If you're considering tackling an ISO 27001 project, discover how to best go about it and the solutions to support your project with our implementation checklist >>
ISO 27001 certification costs
Certification costs usually depend on the number of employees working for the organisation. Certification for an organisation with up to 500 employees could cost in the region of £10,500. Our ISO 27001 Global Report provides further information on what organisations usually pay and whether they think ISO 27001 certification is worth it.
Can you get certified to ISO 27001 with IT Governance?
IT Governance is not a CB. Instead, we specialise in helping organisations like yours to fully prepare for certification. We do this by providing any combination of training, consultancy, tools, books and advice, so that you are ready by the time you engage a CB.
We support the concept of independent, accredited certification, which means that we do not audit our own work. For the same reason, CBs are not permitted to provide consultancy and advice to their clients before conducting a certification audit.
Through our years of experience assisting more than 600 organisations with ISO 27001 implementation and certification projects, we know exactly what CBs expect. As a result, we can offer you unrivalled advice and expertise on how to achieve certification with a certification guarantee.
Download our consultancy brochure to find out more information >>
Ready for ISO 27001 certification? Let’s get started
Having led the world’s first ISO 27001 certification project, we are the global pioneers of the standard. Let us share our expertise and support you on your journey to ISO 27001 compliance.