Confidentiality
Information is available only to authorised people and systems.

Make information security a business discipline—not an IT afterthought.
Enquire about ISO/IEC 27001:2022About ISO/IEC 27001:2022
ISO/IEC 27001:2022 sets internationally recognised requirements for an Information Security Management System (ISMS). It provides a risk-based framework for protecting information wherever it exists—digital, cloud-based, physical or entrusted to another party.
An effective ISMS connects leadership, people, processes and technology to protect the confidentiality, integrity and availability of information. It helps your organisation understand what must be protected, decide which controls are appropriate, respond to incidents and continually adapt as risks, technology and business needs change.
The foundation of information security
ISO/IEC 27001 treats information security as an organisation-wide risk discipline. The three principles below provide a clear lens for understanding what can go wrong and what must be protected.
Information is available only to authorised people and systems.
Information remains accurate, complete and protected from unauthorised change.
Information and systems are accessible when authorised users need them.

What CSi assesses
The assessment looks beyond documented intentions to the way responsibilities, controls, review and improvement operate across the proposed scope.
Potential organisational value
Results depend on how well the management system is designed, implemented and maintained. Certification provides independent assessment—not a guaranteed business outcome.
Identify information assets and evaluate risks within the defined ISMS scope.
Assign ownership and maintain evidence that selected information-security controls operate as intended.
Monitor security performance, respond to incidents and improve the ISMS as threats and business needs change.
Who may consider certification
Certification applies to the defined ISMS scope. It does not guarantee that a cyber incident or information-security breach will never occur.
Your certification pathway
The exact audit programme depends on the organisation’s scope, activities, sites, workforce, complexity and readiness.
Tell us about your organisation, sites, activities and intended scope. CSi reviews the information and prepares a proposal.
We review the system, scope and readiness for the Stage 2 assessment and identify areas requiring attention.
Audit evidence is gathered to assess whether the management system is implemented and meets the applicable requirements.
Findings and corrective actions are reviewed before an independent, impartial certification decision is made.
Planned surveillance and recertification assess continued conformity and the operation of the system over time.
Common questions
Certification applies to the organisation, activities, sites and processes described by the approved certification scope. The certificate should always be read to confirm exactly what has been assessed.
No. CSi must remain independent and impartial. We can explain the certification requirements and process, but your organisation is responsible for designing, implementing and maintaining its management system.
The audit programme and proposal depend on your intended scope, sites, workforce, activities, complexity and readiness. CSi will review these facts before providing a proposal.
Discuss ISO/IEC 27001:2022
Tell CSi about your organisation, intended scope and the outcome you need.