ISO 27001 and ISMS

How do you build and test an operating ISMS according to ISO 27001?

Use ISO 27001 as a risk-driven information security management system. This overview helps you choose between a GAP analysis, guidance and internal audit and brings together the most important knowledge about an operating ISMS.

Risk-driven management system

What does ISO 27001 require of your organisation?

ISO/IEC 27001 describes requirements for an Information Security Management System. This will organise scope, risk analysis, policies, roles, measures, internal review, management review and continuous improvement as a coherent whole. The value is in the daily operation and the ability to support choices and execution.

ISO 27001 services

Choose the approach that suits the phase of your ISMS

Diagnosis, implementation guidance and independent internal audit each have their own purpose. Choose on the basis of the question that management, certifying institution or organisation wants answered.

Diagnosis

ISO 27001 GAP Analysis

Actually, identify the distance to the standard requirements, missing evidence and implementation priorities.

View the ISO 27001 GAP analysis
Building and improvement

ISO 27001 implementation support

Build or improve ISMS with clear scope, risks, ownership, controls and a working improvement cycle.

View ISO 27001 guidance
Independent key

ISO 27001 internal audit

Key design, existence and operation before findings are revealed in an external audit or certification.

View the internal audit

GAP analysis, guidance or internal audit?

From ISMS basis to audit and certification

  1. 01

    Define scope and context

    Identify the services, processes, locations, systems and stakeholders within the ISMS.

  2. 02

    Assess risks and measures

    Connect information security risks to appropriate controls, ownership and evidence intended.

  3. 03

    Make it work ISMS demonstrably

    Perform processes, register deviations and use management information to adjust.

  4. 04

    Audit and improvement

    Test independently, conduct management reviews and incorporate findings into the improvement cycle.

Management system above snapshot

A certificate is a result, not a control model

A strong ISMS helps the organisation manage risk, build evidence of functioning and improve permanently. Certification can follow, but does not replace ownership, decision-making and day-to-day management that effectively ensures information security.

6 articles

ISO 27001 and an operating ISMS

Explanation and tools for scope, risks, controls, audits, certification and demonstrable operation.

Official source

Use the current standard as a formal basis

The official ISO/IEC 27001 standard contains the standard requirements. Public explanations and checklists help guide, but do not replace the standard text and a review of its own scope.

View ISO/IEC 27001 at ISO
ISMS and ISO 27001Discuss where your organisation is located with ISO 27001

Please submit your current ISMS, audit planning and desired security. Then we determine whether a GAP analysis, guidance or internal audit is the best fit.

Schedule an introductory call

Frequently Asked Questions

Practical answers on ISO 27001 and ISMS

What is the difference between ISO 27001 and an ISMS?

An ISMS is the management system that controls information security. ISO 27001 contains requirements for testing and certification of such a management system.

Should each organisation be ISO 27001 certified?

No. Certification is a choice or contractual requirement. Even without a certification purpose, ISO 27001 can be a useful framework for organising information security risk-driven and demonstrable.

When do you choose a GAP analysis?

A GAP analysis fits when you need a factual starting point: What requirements have already been met, where is evidence lacking and what improvements are priority?

Why is an internal audit necessary?

An internal audit provides independent insight into compliance and operation, supports the management review and is a mandatory part of the ISO 27001 cycle.

Wouter Parent

An ISMS has value when it can be used to control management and the organisation can show that important measures work over time.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates