Details

Information Security Management System certification

ISO/IEC 27001:2022

01

Service Introduction

Information security management system certification is an authoritative evaluation mechanism for organizations to establish, implement, maintain and continuously improve information security management system (ISMS), aiming at ensuring the confidentiality, integrity and availability of information, protecting sensitive data and reducing information security risks through a systematic risk management framework. The certification is mainly based on the international standard ISO/IEC 27001:2022, which stipulates the requirements for establishing, implementing, running, monitoring, reviewing, maintaining and improving the information security management system under the overall business risk background of the organization. Certification finally grants the organization a certification certificate valid for three years.

Certification core content

The certification of information security management system revolves around the systematic management of information security, with the following dimensions as the core:

Organizational environment and leadership role: understand the organization and its internal and external environment, identify the needs of relevant parties, determine the scope of ISMS, the commitment of top management, formulate information security policies, and clarify responsibilities and authorities.

Information security risk assessment: the system identifies information assets, evaluates threat vulnerability level, quantifies risk impact, outputs risk assessment report and rectification plan, and determines risk disposal priority.

Information security planning: setting information security objectives, planning measures to achieve the objectives, and selecting appropriate control measures (access control, encryption technology, firewall, security audit, etc.).

Resources and support: resource allocation, personnel ability and training, information security awareness training, communication mechanism, and documented information control (11 key areas such as security policy, asset management, and access control).

Operation control: integrate information security requirements into business processes, change management, outsourcing process control and security incident management.

Performance evaluation: information security performance monitoring and measurement, compliance evaluation, internal audit and management review.

Improvement mechanism: correction of nonconformities, continuous improvement measures (PDCA cycle) and preventive measures.

Certification process

Information security management system certification is usually divided into the following stages:

Pre-preparation stage: define the objectives and scope of certification, set up a project team, carry out information security awareness training for all employees, and identify the basic qualifications required for certification (legal business entity, no record of major administrative punishment).

System establishment stage: conduct risk assessment, formulate information security strategy, select control measures, and compile system documents (three-level document framework of policies/requirements/procedures) to ensure compliance with ISO 27001 standards.

System trial operation stage: release and publicize system documents, fully run ISMS and collect operation evidence (training records, inspection reports, risk assessment reports, etc.) to ensure that the system has been running for more than 3 months.

Application and acceptance: submit application materials (business license, system documents, applicability statement SoA, risk assessment report, internal audit/management review records, etc.), and the certification body will conduct application review.

First-stage audit (document audit): conduct document audit and site preparation evaluation, review the compliance of system documents with standard requirements, especially verify the organization's Statement of Applicability (SOA), and confirm the adequacy of the second-stage audit preparation.

The second stage audit (on-site audit): conduct on-site audit, including personnel interview, document record inspection, on-site facility inspection, effectiveness verification of information security control measures, evaluation of compliance and effectiveness of the system, and identification of nonconformities.

Rectification and review: for the nonconformities found in the audit, the organization shall complete the rectification within the specified time limit and submit the evidence, which will be reviewed by the audit team.

Certification decision and certification: Certification certificate will be issued after the technical review, which confirms that the organization meets the requirements of ISO/IEC 27001 standard. The certificate is valid for three years and can be found on the website of CNCA.

Supervision and audit: conduct supervision and audit once a year after obtaining the certificate (the interval shall not exceed 12 months) to confirm that the system continues to meet the certification requirements.

Re-certification audit: Re-certification audit is conducted before the certificate expires, and the certification qualification is extended, usually for three years.

Certification value

Improve the level of information security management: identify threats through systematic processes and reduce security incidents such as data leakage; Establish a sound disaster recovery and emergency response mechanism to ensure the rapid recovery of key businesses in security incidents.

Enhance market competitiveness: Certification is an internationally recognized information security management standard. Certified enterprises can show their commitment to information security to customers and partners, and have obvious advantages in bidding and supply chain access; Large enterprises often take certification as the entry threshold for suppliers.

Meet the requirements of laws and regulations: help organizations meet the requirements of domestic and foreign laws and regulations such as Network Security Law, Data Security Law, GDPR (EU General Data Protection Regulation), and avoid legal punishment caused by data leakage or management negligence.

Reduce operational risks: systematically identify and manage information security risks, establish a risk management and control mechanism focusing on prevention, reduce the losses caused to the organization by potential security incidents, and ensure business continuity.

Enhance brand reputation and customer trust: through independent third-party certification, prove to stakeholders that the organization has sound information security protection measures, and enhance the trust of customers, partners and regulatory agencies.

Optimize internal management: through standardized processes and quantitative management, clarify the division of responsibilities for information security and reduce human operation loopholes; Strengthen employees' awareness of information security and standardize the organization's information security behavior.

Obtaining government support: some industries (such as finance, medical care and government cloud) take ISO 27001 certification as a mandatory condition for bidding or cooperation; Certification helps enterprises to meet international standards and expand overseas markets.

03

Service Process

04

Rules File

Need this certification?

Contact us