Path to ISO 27001 certification

Achieving ISO 27001 means completing about 140 separate tasks, that we’ve broken down into 11 simple steps. They’re an integral part of ISMS.online. Each includes specific, pre-set work areas and tasks all ready to go.

You’ll start by describing your current information security environment:

  • Lay firm foundations by understanding your organisation’s infosec needs
  • Describe any infosec policies and controls you already have in place
  • Add in any policies or controls you’re missing

Then you’ll go live with your ISMS and carry out your first internal audit:

  • Formally launch your ISMS and move it into operational mode
  • Conduct your first internal audit by reviewing your ISMS’ documentation
  • Go through and prioritize any improvements you need to make

Finally you’ll complete the audit process to achieve compliance or certification:

  • If you’re going for certification, get ready for your first external audit
  • Find the right certification body
  • Complete your first external audit, which checks your ISMS’ documentation
  • Carry out your second internal audit, focusing on how your ISMS works in practice

Prodigy 13 Newsletter

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Related Articles

Security

SAML explained

SAML explained in plain English: https://www.onelogin.com/learn/saml SAML is an acronym used to describe the Security Assertion Markup Language (SAML). Its primary role in online security is

Read More
Security

Threat Hunting – Practical Guide

Resource: https://www.threathunting.net/files/hunt-evil-practical-guide-threat-hunting.pdf To begin, let’s clarify what threat hunting is: Threat hunting is the human-driven, proactive and iterative search through networks, endpoints, or datasets in

Read More