A cross-functional team reviewing information security risks and response information

Information security management
certification

Make information security a business discipline—not an IT afterthought.

Enquire about ISO/IEC 27001:2022
ISO/IEC 27001:2022

About ISO/IEC 27001:2022

Govern information risk with clarity and control.

ISO/IEC 27001:2022 sets internationally recognised requirements for an Information Security Management System (ISMS). It provides a risk-based framework for protecting information wherever it exists—digital, cloud-based, physical or entrusted to another party.

An effective ISMS connects leadership, people, processes and technology to protect the confidentiality, integrity and availability of information. It helps your organisation understand what must be protected, decide which controls are appropriate, respond to incidents and continually adapt as risks, technology and business needs change.

The foundation of information security

Protect what must remain confidential, accurate and available.

ISO/IEC 27001 treats information security as an organisation-wide risk discipline. The three principles below provide a clear lens for understanding what can go wrong and what must be protected.

C

Confidentiality

Information is available only to authorised people and systems.

I

Integrity

Information remains accurate, complete and protected from unauthorised change.

A

Availability

Information and systems are accessible when authorised users need them.

A business team mapping information assets, risks and responsibilities

What CSi assesses

Test whether security controls work beyond the policy document.

The assessment looks beyond documented intentions to the way responsibilities, controls, review and improvement operate across the proposed scope.

01

ISMS scope, risk assessment and risk-treatment arrangements

02

The selection, implementation and review of applicable controls

03

Incident response, internal audit, management review and improvement

Potential organisational value

Clearer risk decisions. Stronger accountability. Greater resilience.

Results depend on how well the management system is designed, implemented and maintained. Certification provides independent assessment—not a guaranteed business outcome.

01

A structured view of information-security risks

Identify information assets and evaluate risks within the defined ISMS scope.

02

Clear accountability for selected security controls

Assign ownership and maintain evidence that selected information-security controls operate as intended.

03

Evidence that the system is monitored, reviewed and improved

Monitor security performance, respond to incidents and improve the ISMS as threats and business needs change.

Who may consider certification

For organisations entrusted with valuable information.

  • Organisations handling sensitive customer or commercial information
  • Businesses responding to contractual or supply-chain security expectations
  • Organisations seeking a governed approach to cyber and information risk
Certification boundary

Certification applies to the defined ISMS scope. It does not guarantee that a cyber incident or information-security breach will never occur.

Your certification pathway

A risk-based pathway from ISMS scope to ongoing certification.

The exact audit programme depends on the organisation’s scope, activities, sites, workforce, complexity and readiness.

  1. 1

    Enquiry & application

    Tell us about your organisation, sites, activities and intended scope. CSi reviews the information and prepares a proposal.

  2. 2

    Stage 1 · readiness

    We review the system, scope and readiness for the Stage 2 assessment and identify areas requiring attention.

  3. 3

    Stage 2 · implementation

    Audit evidence is gathered to assess whether the management system is implemented and meets the applicable requirements.

  4. 4

    Review & decision

    Findings and corrective actions are reviewed before an independent, impartial certification decision is made.

  5. 5

    Maintain certification

    Planned surveillance and recertification assess continued conformity and the operation of the system over time.

Common questions

Understand the commitment before you apply.

What does management system certification cover?+

Certification applies to the organisation, activities, sites and processes described by the approved certification scope. The certificate should always be read to confirm exactly what has been assessed.

Can CSi design or implement our management system?+

No. CSi must remain independent and impartial. We can explain the certification requirements and process, but your organisation is responsible for designing, implementing and maintaining its management system.

How long will certification take and what will it cost?+

The audit programme and proposal depend on your intended scope, sites, workforce, activities, complexity and readiness. CSi will review these facts before providing a proposal.

Discuss ISO/IEC 27001:2022

Turn your certification requirement into a clear plan.

Tell CSi about your organisation, intended scope and the outcome you need.