Readiness status, honestly stated

Our ISO 27001 position

We are not ISO 27001 certified. A certificate comes from an accredited certification body after a two stage audit, and we have not been through that audit. What we operate is the control base and the risk method that the standard requires, and we are building out the management system elements that remain.

Areas assessed

10

Operating and evidenced

4

Areas with an open gap

6

How this relates to our SOC 2 work

ISO 27001 uses the same control base through Annex A, so the work is shared rather than duplicated. The difference is that ISO also requires a management system: a scope statement, a risk method, an internal audit program, and a management review. We hold the control work and the risk method today, and the internal audit program and management review are the remaining build.

Management system clauses

  • Clauses 4 and 5. Management system

    Being strengthened

    The scope of the management system is defined, and leadership demonstrates commitment through an approved policy and assigned roles.

    Evidence an assessor would request. The scope statement, the information security policy, and the record of assigned responsibilities.

    Open gap. The scope statement and policy exist. They need formal versioning and an approval record with dates.

  • Clause 6. Planning

    Being strengthened

    Risks and opportunities are assessed against a defined method, with a treatment plan and a statement of applicability.

    Evidence an assessor would request. The risk method, the risk register, the treatment plan, and the statement of applicability.

    Open gap. The statement of applicability covering all Annex A controls with a justification for each has not been written yet.

  • Clause 7. Support

    Operating and evidenced

    Resources, competence, awareness, communication, and documented information are managed.

    Evidence an assessor would request. Competence records, the training plan, awareness activity, and document version control.

  • Clause 8. Operation

    Operating and evidenced

    The organization plans, implements, and controls the processes needed to meet its requirements.

    Evidence an assessor would request. Operating procedures, records that they ran, and the results.

  • Clause 9. Performance evaluation

    Being strengthened

    Monitoring, measurement, internal audit, and management review are performed.

    Evidence an assessor would request. The internal audit program covering the whole system over a cycle, and management review outputs.

    Open gap. A documented internal audit program with a schedule across the full cycle is the main outstanding item.

  • Clause 10. Improvement

    Being strengthened

    Nonconformities are corrected, and the management system is continually improved.

    Evidence an assessor would request. The nonconformity log, root cause analysis, and evidence that corrections held.

    Open gap. Corrections are recorded against incidents. A single nonconformity log covering control failures as well is being built.

Annex A control groups

  • A.5. Annex A organisational controls

    Operating and evidenced

    Policies, roles, supplier relationships, and continuity of information security are governed.

    Evidence an assessor would request. The policy set, supplier agreements with security terms, and the incident and continuity procedures.

  • A.6. Annex A people controls

    Operating and evidenced

    Screening, terms of employment, awareness, discipline, and exit are managed for security.

    Evidence an assessor would request. Screening records, signed terms, awareness evidence, and dated exit records.

  • A.7. Annex A physical controls

    Being strengthened

    Physical areas, equipment, and media are protected.

    Evidence an assessor would request. Clear desk and clear screen rules, device encryption evidence, and secure disposal records.

    Open gap. We work remotely, so the physical controls apply to home working and devices. The home working standard needs writing down rather than assuming.

  • A.8. Annex A technological controls

    Being strengthened

    Endpoints, access, cryptography, logging, monitoring, vulnerability management, and secure development are controlled.

    Evidence an assessor would request. Configuration baselines, encryption settings, log retention, alerting, and scan and remediation records.

    Open gap. Logging and alerting on our own estate is the open item, and it is already phase two work.

If your process requires a certificate

Tell us at the start. We will not claim an equivalence an assessor would reject. What we can offer instead is our control register with dated evidence, a completed questionnaire answered from that register, and a walkthrough with the person who operates the control.