How to get ISO 27001 certification?
To get ISO 27001 certification, your organization must build an Information Security Management System (ISMS) that meets the standard's requirements and then pass an official audit conducted by an accredited certification body.
The journey can be broken down into three main phases: preparation and implementation, internal review, and the external certification audit.
Phase 1: Preparation and Implementation
This is the most intensive phase, where you build your ISMS.
-
Step 1: Get Management Buy-In and Define Scope First, secure commitment and resources from leadership. Then, formally define the scope of your ISMS—which parts of the organization, services, or locations will be covered by the certification.
-
Step 2: Conduct a Risk Assessment This is the core of the process. You must identify information security risks, analyze their potential impact, and create a Risk Treatment Plan to manage them.
-
Step 3: Develop Documentation Create the necessary documentation, including an Information Security Policy, the Statement of Applicability (SoA), and various procedures and records required by the standard.
-
Step 4: Implement Controls and Train Staff Put your chosen security controls from the Risk Treatment Plan into practice. A critical part of this step is conducting security awareness training for all employees to ensure they understand their responsibilities.
Phase 2: Internal Review
Before calling in the external auditors, you must check your own work.
-
Step 5: Conduct an Internal Audit Perform a complete internal audit of your ISMS to find any gaps or non-conformities. This "self-check" gives you a chance to fix problems before the official audit.
-
Step 6: Hold a Management Review Your top management must formally review the performance and effectiveness of the ISMS, review the internal audit results, and approve any necessary changes.
Phase 3: External Certification Audit
This is the final step, performed by an accredited external auditor.
-
Step 7: The Stage 1 Audit The auditor reviews your documentation to verify that the design of your ISMS meets the requirements of the standard. They will point out any areas of concern that need to be addressed before the next stage.
-
Step 8: The Stage 2 Audit The auditor conducts an in-depth review to verify that you are actually following your own policies and procedures in practice. They will interview staff, inspect records, and look for evidence that your security controls are operating effectively.
If you successfully pass the Stage 2 audit, the certification body will award your organization the ISO 27001 certificate.