What ISO 27001 actually certifies, and what it doesn't
ISO/IEC 27001 is the international standard for managing information security. The certificate is issued to an organisation, for a defined scope, after an independent audit. It is not issued to a piece of software, and no supplier can hand you one.
What the certificate covers
- A management system: the policies, roles, risk assessments and controls your organisation runs
- A scope: which parts of the organisation, which systems and which locations are inside it
- Evidence that the controls are operating, checked by an auditor at a Stage 1 and a Stage 2 audit
Who issues it
An accredited certification body. In the UK, accreditation comes from UKAS. The body audits you, not your developer. Your developer's own certificate shows how they handle information, which matters, but it is not a substitute for yours.
What a developer can do
- Build your systems with the controls in from the start: access control, encryption, logging, backups, change control
- Produce the evidence an auditor asks for, as part of the work rather than reconstructed later
- Write, or help write, the policies and agreements the standard requires
- Stay through the audit and the yearly surveillance audits that follow
What it costs you after the certificate
A surveillance audit every year, recertification every three years, and the work of keeping the controls running in between. Budget for the upkeep, not just the certificate.
SOC 2, briefly
SOC 2 is the US equivalent that enterprise buyers ask for. It is a report by a licensed accountant rather than a certificate. Type 1 describes the controls at a point in time; Type 2 tests them over a period of months.
Related: ISO 27001 and SOC 2 consultancy
Find out what your systems should be doing.
A free call with Paul Hanner, then a written summary of what we'd keep, change and build first.
Book a free systems review