Home / Trust Certifications / ISO 27001:2022

Trust Certifications

ISO 27001:2022

Build an information security management system that works day to day, and take it through certification.

Consultant presenting an audit roadmap to a client team
Image placeholder: Consultant presenting an audit roadmap to a client team

Overview

What it is and who needs it

ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS): the policies, processes and controls an organisation uses to manage information risk. Certification by an accredited certification body is widely accepted by customers as evidence that security is managed systematically.

We guide you from the first gap assessment to the certification audit, building an ISMS that fits the way you already work instead of a set of documents written only for the auditor.

Who needs it

  • SaaS and technology companies selling to enterprise customers
  • Organisations asked for ISO 27001 in tenders and contracts
  • Businesses that want a recognised structure for managing security risk
  • Teams preparing for PCI DSS or the DPDP Act that want a common foundation
Workshop with risk register on a wall screen
Image placeholder: Workshop with risk register on a wall screen

Scope

What is covered

ISMS scope and context

The boundaries of the system, interested parties and the objectives it must meet.

Risk assessment and treatment

A repeatable method, a risk register and a treatment plan owned by the business.

Statement of Applicability

Which Annex A controls apply, why, and how each is implemented.

Policies and procedures

A concise document set that reflects how your organisation really operates.

Annex A controls

Implementation of the applicable controls across all four themes.

Awareness, audit and review

Staff training, internal audit and management review before certification.

Annex A

93 controls across four themes

The 2022 edition groups the Annex A controls into four themes. Your Statement of Applicability records which ones apply to you.

37

Organizational

Policies, roles, supplier relationships, incident management and compliance.

8

People

Screening, awareness, responsibilities and remote working.

14

Physical

Secure areas, equipment protection and clear desk.

34

Technological

Access, cryptography, logging, secure development and network security.

Our approach

How we work, step by step

01

Gap assessment

We compare current practice with the standard and report what is missing.

02

Scope definition

We agree which locations, teams, products and systems the ISMS will cover.

03

Risk assessment and treatment

Risks are identified, rated and assigned a treatment with an owner.

04

Statement of Applicability

Each Annex A control is marked as applicable or not, with justification.

05

Policies and procedures

Documents are written or updated to match how you work.

06

Annex A controls

Applicable controls from the 93 across four themes are implemented and evidenced.

07

Awareness training

Staff learn what the ISMS expects of them.

08

Internal audit

An independent internal audit tests the ISMS and records findings.

09

Management review

Leadership reviews performance, risks and audit results, and agrees actions.

10

Certification audit support

We prepare your team, attend the Stage 1 and Stage 2 audits and help to close nonconformities.

Deliverables

What you receive

  • Gap assessment report and project plan
  • ISMS scope statement, risk register and risk treatment plan
  • Statement of Applicability
  • Policy and procedure set
  • Internal audit report and management review record
  • Support through the Stage 1 and Stage 2 certification audits
Statement of Applicability and policy documents
Image placeholder: Statement of Applicability and policy documents

Why iSecurify

Three reasons customers choose us

01

An ISMS that fits your business

Controls are designed around your existing tools and processes.

02

Experienced implementers

Our consultants have built and audited management systems across sectors.

03

With you through the audit

We stay until the certificate is issued and findings are closed.

Questions

Frequently asked questions

How long does certification take?

Most small and mid-size organisations take four to eight months from gap assessment to certification, depending on scope and how much is already in place.

Does iSecurify issue the certificate?

No. Certificates are issued by an accredited certification body after an independent audit. We prepare you and support you during that audit. Keeping consultancy and certification separate is what gives the certificate its value.

What changed in the 2022 edition?

Annex A was reorganised from 114 controls in 14 domains to 93 controls in four themes, including 11 new controls covering areas such as threat intelligence, cloud services, data masking and secure coding.

Do we need a full-time security team?

No. You need clear ownership and management commitment. Many customers run the ISMS with a small internal team and our continuing support.

What happens after certification?

The certificate is valid for three years, with surveillance audits in between and a recertification audit at the end. We can run internal audits and keep the ISMS current.

Customer stories

What our customers say

  • Outsourcing our cybersecurity operations to iSecurify has been a strategic advantage. From real-time threat monitoring to compliance assistance, their managed services have brought us peace of mind and enabled our internal team to focus on business growth.

    Swapon Adhikary

    Director · The Hird

  • Following the launch of our website in both Dubai and India, we required immediate security validation to ensure platform integrity. iSecurify delivered a rapid yet comprehensive application security assessment, providing detailed and actionable findings. Their expert team collaborated directly with our developers to swiftly remediate vulnerabilities, enabling us to go live with confidence and security.

    Krutarth Pandya

  • We deployed iSecurify’s iSIEM-based monitoring with automated IP blocking, and the results were immediate. Malicious IPs targeting our systems were detected and blocked in real time. The integration was seamless, and the improvement in our threat response has been significant.

    Nandeep Mehta

Organisations we work with

Talk to us about ISO 27001:2022.

Share a few details and a consultant will come back with a scope and next steps.

info@isecurify.co