
Background
ISO 27001 provides requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). The adoption of an ISMS is a strategic decision for an organization. The establishment and implementation of an ISMS is influenced by the organization’s needs and objectives, security requirements of interested parties, the processes used and the organizational size and structure maintained, all of which can change over time.
A sound ISMS and Statement of Accountability preserves the confidentiality, integrity and availability of information by applying a risk management process and gives confidence to interested parties that risks are adequately managed.
Attributes
Name: | ISO 27001 Assurance Program |
Criteria: | ISO 27001 and Client Charter |
Market: | All organizations utilizing information technology |
Scope: | International |
Output: | Certificate of Confidence |
Validity: | 3 years, subject to on-going requirements |
Outcome: | Certification gives confidence to the organization, its customers, regulators and/or other interested parties in the ability to effectively manage information security. |
The process
As an organisation, the steps involved for you are: