Offer type: Management system certification
Reference code: ISO_IEC_27001
ISMS certification: independent verification of security management via assets, risk assessment and control selection.
Scope
ISO/IEC 27001 defines requirements to establish and operate an information security management system (ISMS). Risk assessment, control selection (related to Annex A / ISO 27002) and continual improvement form the backbone of certification audits.
Benefits
- Inventory of information assets and risks
- Controls oriented to confidentiality, integrity and availability
- Response to supplier and customer security expectations
- Foundation to integrate incident response and continuity
Typical process
- Current-state / gap analysis
- Policy, objectives and documentation
- Training and awareness
- Internal audit and management review
- Accredited certification audit (where applicable)
This page describes the certification / assessment service. Licensed standard text is not distributed. Request a quote for scope, duration and pricing.