ISO 27001 STANDARD

ISO 27001 – explained

The international standard for information security management.

WHAT IT MEANS TO GET CERTIFIED

ISO 27001 is not a legal requirement like NIS2, but it serves to demonstrate, through an independent external audit, that the organization manages information security according to an internationally recognized system.

Certification for contracts or tenders

Enterprise clients or public tenders that require it as a condition of supply

Certification to strengthen trust

Companies and universities that want to demonstrate structured information security management to clients, partners, and funders

Control domains

93 controls organized into 4 categories, updated to the ISO/IEC 27001:2022 revision

37 organizational

Security policies, roles and responsibilities, information asset management, information classification, supplier relationships, and process-level incident management

8 people

Pre-employment screening, employment terms and conditions, awareness and continuous training, disciplinary procedures, and termination of employment management

14 physical

Security perimeters, physical access control, protection against environmental threats, office and server room security, secure equipment disposal

34 technological

Access management and authentication, cryptography, network security, logging and monitoring, backup, vulnerability management, and secure software development

The phases of the certification process

Gap analysis and risk assessment

Asset mapping, risk assessment, comparison with Annex A controls

Implementation of controls

Policies, procedures, and technical measures for the controls selected in the Statement of Applicability

Internal audit

Independent internal verification of the management system prior to the external audit

Certification audit

Documentary review, followed by verification of the effectiveness of controls in the field, conducted by an accredited third-party body

Surveillance and renewal

Annual surveillance audits and re-certification every 3 years.

3 years

of certificate validity, with annual surveillance audits to keep it active.

93 controls

selectable based on the organization's actual risk profile, not all mandatory.

Contact us

Contact Form Virgilia