ISO 27001
Process
27001
In the digital world, information is one of the most valuable corporate resources. Cyber attacks, data loss, unauthorised access and IT incidents can cause significant financial and reconstruction damage. ISO/IEC 27001 is the world's leading information security standard that helps organisations to address information security risks and protect sensitive data. The certificate shall demonstrate to its customers and partners that your organisation manages information security in a structured manner and applies appropriate measures to protect business information.
What is ISO 27001?
ISO/IEC 27001: 2022 is an international standard that defines the requirements of the Information Security Management System.
The purpose of the standard is to protect the following information:
business information
customer data
personal data
financial information
IT systems
intellectual property
electronic and paper documents.
ISO 27001 is based on principles of confidentiality, integrity and availability (CIA).
Why is ISO 27001 worth getting?
Greater customer confidence
Partners and customers increasingly expect proof of compliance with information security.
Protection against cyber attacks
The standard helps to identify and manage information security risks.
Compliance with supplier requirements
Many multinational companies and public organisations expect ISO 27001 certificates to exist.
International Recognition
ISO 27001 is a global information security standard.
Risk-based operation
The standard supports the conscious management of business and information security risks.
Competition advantage
The certificate can often be a decisive factor in obtaining new customers.
To whom is ISO 27001 recommended?
ISO 27001 is particularly recommended:
software development companies
SaaS service providers
IT operators
cloud service providers
Data centres
Fintech companies
healthcare providers
advisory firms
financial service providers
Outsourcing to service providers
artificial intelligence development companies.
In practice, it benefits all organisations that handle confidential information.
What is an ISO 27001 audit?
The audit shall include, inter alia, the following areas:
Information security policy
Risk assessment
asset inventory
access management
password management
Save
Incidence Management
handling suppliers
business continuity
employee awareness
IT and physical security measures.
Audit Duration
1-3
audit day for small and medium-sized enterprises
The duration of the audit depends on several factors.
Number of employees
Number of sites
ISMS scope
complexity of the IT environment
Number of outsourced processes
use of cloud services
the existence of integrated management systems.
For most small and medium-sized enterprises, certification audits typically take 1-4 audit days.
The exact audit time shall be determined on the basis of the requirements of ISO/IEC 27006-1 and the accreditation rules.
1-3
audit day for small and medium-sized enterprises
audit day for small and medium-sized enterprises
The Certification Process
01
How much for ISO 27001 certification?
The cost of certification depends on several factors.
integrated audits.
Why Choose Us?
More than 10 years of audit experience
Extensive experience in information security audits.
IT and software development expertise
Significant experience:
Internationally Recognized Certificates
Certificates shall be issued by accredited certification bodies.
Integrated audits
SaaS systems
cloud-based services
health software
business applications
IT services audit.
Frequently Asked Questions
No, but more and more clients and partners expect it.
No. It is useful for all organisations that handle confidential information.
No. The selection of controls shall be based on the outcome of the risk assessment.
Three years, with annual surveillance audits.
Yes, in particular ISO 27701, ISO 22301 and ISO 20000-1.
Request a Quote
Get in touch with us and request an individual, no-obligation quote.
Request a Detailed Quote
Fill in our detailed quote request form — we prepare an individual offer based on your company data, the standards you select and a few questions about your processes.
Continue to tender →No obligation · Our reply within 1 working day