Skip to content

Insights

ISO 27001: Defining the Certification Process

Key Takeaways

  • Start with a Strong Foundation: Define the ISMS scope, conduct a risk assessment, and implement the necessary controls before beginning the certification audit.
  • Understand the Two-Phase Audit: Phase 1 evaluates ISMS readiness and documentation, while Phase 2 assesses whether controls are implemented and operating effectively.
  • Address Nonconformities: Organizations must remediate significant issues and document corrective actions before certification can be issued.
  • Certification Requires Ongoing Commitment: After certification, organizations must continuously monitor risks, evaluate controls, and improve their ISMS.

ISO 27001 is an internationally recognized framework for information security management that defines practical process for identifying/managing risks, defining internal controls, and protecting sensitive/confidential/private data. Organizations that choose to pursue ISO 27001 certification are committed to cybersecurity controls and safeguarding information and data assets. The commitment and process required to achieve ISO certification, though substantial in effort, is well worth it to demonstrate an organization’s commitment to their information security management system.

The certification process can be broken down into stages. Each stage represents a defined and specific process within the certification cycle. The key to a successful certification is understanding each phase as well as understanding the overall path to final ISO 27001 certification.

Stage 1: Readiness and Pre-Assessment Phase

This first stage in the certification process largely relates to planning and preparation. Organization will begin this phase by first focusing on identifying the Information Security Management System (ISMS) scope. The scope is paramount, as it defines the boundaries and requirements for the ISMS and the ISO 27001 certification. After the ISMS scope has been clearly identified and documented, the next step is for the organization to perform a comprehensive risk assessment against the requirement for ISO 27001.

The risk assessment provides a process for an organization to identify risks to the organization’s ability to meet the ISO 27001 requirements, analyze and evaluate those risks, and finally mitigate risks. The resulting output from the risk assessment is a documented risk register, treatment plan, and statement of applicability for the ISO 27001 Annex A controls.

The last phase of the readiness phase is to appropriately implement the controls, including documenting policies, procedures, practices, and control activities as necessary to respond to the risks identified. The implementation of the controls ensures that the organization has not only evaluated ISO 27001 requirements, but they have put into action actual controls through policies, procedures, and security activities to meet the requirements and mitigate risks.

Stage 2: ISO 27001 Certification Audit

The certification audit is performed by an external auditor who will examine and review an organization’s ISMS in typically two phases. Upon successful completion of the two phases of the audit, the organization will receive an ISO 27001 certification covering a 3-year period.

Phase 1 primarily consists of a high level and is designed to evaluate the organization’s ISMS. The auditor will evaluate the ISMS to ensure it has been designed and documented to meet the ISO 27001 requirements. Phase 1 of the audit is to evaluate whether the organization is ready and prepared to move to phase 2 of the audit. Any issues identified by the auditor during phase 1 should be addressed, and the organization should be prepared to evaluate their certification timeline to ensure any remediation is appropriately addressed prior to phase 2 commencing.

Phase 2 of the external certification the external audit will evaluate an organization’s ISMS and those controls defined within the statement of applicability to determine if security policies, procedures, and control activities are functioning and operating effectively. Phase 2 requires that the organization produces and retains documentation that provides the auditor with evidence that the control activities are in place and operating.

Significant nonconformities will require a corrective action plan, documentation evidencing correction, and full remediation prior to issuing a certificate. Less significant nonconformities only require a corrective action plan and documentation of the corrective action. Upon successful completion of phase 1 and phase 2, the auditor will issue the ISO 27001 certification to the organization.

Stage 3: Ongoing Monitoring

Upon receiving ISO 27001 certification, the organization must continue to monitor and evaluate the ISMS to ensure continued operating effectiveness of the plan. Effective monitoring will require the organization to perform ongoing activities to monitor, evaluate, and update policies, procedures, and control activities. The organization should use the results from ongoing monitoring to improve the ISMS. Additionally, updates to risk assessment and threats should be continually addressed to ensure that the appropriate controls have been established and are operating effectively.

For more information on these services and more, be sure to visit our ISO 27001 service pages. If your entity is interested in obtaining any additional information on ISO 27001, or if there are any other questions related to ISO 27001, don’t hesitate to contact Dave Hammarberg, CPA, CFE, CISSP, GSEC, MCSE, CISA, CHQP, CCSFP, LCCA.

About the Author

Josh Bantz

Josh Bantz, CPA, CCSFP, CHQP, CISA, CCP is a Director with the firm. He is a key member of the firm’s Audit & Assurance Segment, primarily working with clients in the firm’s Service Organization Controls (SOC) Practice, HITRUST and CM… Read more

Related Services

Subscribe to Our Newsletter