What is ISO/IEC 27001?
ISO/IEC 27001 specifies requirements to establish, operate and improve an information security management system, including scope, risk assessment and treatment, Statement of Applicability and performance evaluation.
Who needs this certification?
Technology and cloud providers
Banks and fintech companies
Telecom and government entities
Healthcare and data-sensitive organizations
What can it add to the organization?
- Demonstrate structured risk management
- Build confidence in contracts and supply chains
- Clarify scope, ownership and controls
- Improve incident and supplier management
From application to certification decision
Information and records reviewed by the audit team
Details vary by organization scope, sector and sites, and commonly include:
- ISMS scope and organizational context
- Risk assessment and treatment
- Statement of Applicability
- Policies, controls, records and internal audit
INSPECT is an assessment and certification body. It does not design, implement or maintain the management system it will assess. Any accreditation claim remains tied to the latest official approved scope.
Frequently asked questions about ISO/IEC 27001
Controls are not a universal mandatory checklist. The organization selects needed controls based on risk and requirements and justifies inclusion or exclusion in the SoA.
Scope should clearly cover relevant services, processes, sites and interfaces associated with the information being protected.
ISO/IEC 27001 contains certifiable requirements; ISO/IEC 27002 provides detailed guidance on information security controls.
