Before the audit
The ISO 27001 certification process involves a preparation stage prior to the actual audit. This can include:
- Determining the scope of the ISMS
- Defining information security guidelines and goals
- Developing a risk assessment and risk treatment methodology
- Preparing a declaration of applicability
- Preparing a risk management plan and risk assessment report
- Defining security roles and responsibilities
- Creating a list of assets
- Ensuring acceptable use of assets
- Defining guidelines, e.g. for access control according to Annex A of ISO 27001
If desired, the ISO 27001 certification process can include a preliminary audit prior to initial certification, in which the ISMS documentation is reviewed and checked for completeness and conformity to standards.
The ISO 27001 certification audit
The ISO 27001 certification audit consists of a Stage 1 audit for checking the ISMS documentation and determining whether the company is ready for certification (readiness assessment) followed by a Stage 2 audit for testing the efficacy of the ISMS.
Our auditors document the audit in a report and evaluate your company's ISMS. In the next step, the certificate and the DEKRA seal are issued with a validity of up to three years.
Next are the annual surveillance audits for maintaining certification: the first takes place within one year of the initial audit, and the second in the following year.