What the standard actually requires
ISO/IEC 27001 is a standard for an information security management system — the arrangements by which an organisation decides what it needs to protect, how much protection is warranted, and whether the protection is working. It is not a checklist of security controls, and a certificate against it is not a statement that you have good firewalls.
The requirements sit in clauses 4 to 10, and the shape of them is the shape of every modern management system standard:
- Context and scope. What the management system covers, who has an interest in it, and what external and internal issues bear on it. Scope is the single most consequential decision you will make — a certificate says what it says about the scope you defined, and no more.
- Leadership. A policy, assigned responsibilities, and management that is demonstrably involved rather than merely supportive on paper.
- Risk assessment and treatment. The core of the standard. You identify risks to the confidentiality, integrity and availability of information, evaluate them against criteria you have set, and decide what to do about each one.
- The Statement of Applicability. For every control in Annex A you state whether it applies, and — if it does not — why. This document is where an auditor spends a great deal of time, because it is where an organisation’s real reasoning is visible.
- Support and operation. Competence, awareness, documented information, and actually running the treatments you decided on.
- Performance evaluation. Monitoring, internal audit, and management review.
- Improvement. What happens when something does not conform, including how you correct it and stop it recurring.
Annex A carries 93 controls in four themes — organisational, people, physical and technological. The 2022 edition restructured these from the fourteen clauses of the 2013 edition and added controls covering threat intelligence, cloud services, data masking and secure coding, among others.
Do you actually need it?
Be honest with yourself about the answer, because certification is not free and it is not automatically worth having.
It is usually worth it when a customer or a tender requires it and you are losing work without it; you handle other organisations’ data and need a credible way to say how you protect it; you are selling into regulated sectors; or you have grown to the point where security decisions are being made informally by whoever notices.
It is usually not the right first step when you have no security practices to certify yet. The standard certifies a management system that exists. If nothing exists, certification is the wrong place to start, and no honest auditor will tell you otherwise.
What a UMA certificate against ISO/IEC 27001 does and does not assert
It asserts that we audited your information security management system against ISO/IEC 27001:2022, for the scope stated on the certificate, and that on the evidence we saw it conforms.
It does not assert that your systems are secure, that you will not be breached, that your products are safe to use, or that you comply with data protection law. A management system standard certifies how you manage — the decisions, the reviews, the corrections. It cannot certify an outcome nobody can guarantee.
How audit time is worked out for this standard
Audit duration for ISO/IEC 27001 is determined under ISO/IEC 27006-1, which is the standard governing bodies that certify information security management systems. It is not the same basis used for ISO 9001, and the numbers differ.
The inputs are the effective number of personnel within the scope, plus factors specific to information security: the complexity of the systems in scope, the number of sites and how they differ, the amount of development work you do, the degree of outsourcing, and the sensitivity of the information handled. We show you the calculation with the quotation.
The cycle
Stage 1, then stage 2, then a certification decision taken by someone who had no part in the audit. Certification runs for three years, with a surveillance audit in each of the two intervening years — the first due within twelve months of the certification decision — and a full recertification audit before the three years are up.