What is ISO/IEC 27001:2022?
Unlike a set of technical tools, the standard requires a management approach: identify the risks threatening your information, decide how to treat them, and demonstrate that those controls work and improve over time.
Annex A brings together 93 controls grouped into four themes: organizational, people, physical and technological. You select the applicable ones based on your risk assessment and document them in the Statement of Applicability.
Benefits of certification
- Demonstrable trust with customers who require assurance about how their information is handled.
- Lower risk of incidents, data leaks and penalties for non-compliance.
- Clear responsibilities and an orderly response to incidents.
- Alignment with contractual, regulatory and personal data protection requirements.
Who it applies to
Any organization that handles valuable information: technology and software companies, professional services, manufacturers holding customer intellectual property, healthcare, finance and logistics.
How we support you
Scope and risks
We define the ISMS scope and lead risk assessment and treatment with your team.
Controls and policies
We design policies, procedures and the Statement of Applicability, aligned with how you really operate.
Audit and certification
Internal audits, management review and support through to the certification audit.
Integration with other systems
ISO 27001 shares its structure with ISO 9001 and other standards, so it can be integrated into an existing management system to avoid duplicated effort.
Ready to put this into practice?
Let's talk about your organization's specific challenges and how we can help you solve them.
Request a quote↗