Readiness status, honestly stated
Our ISO 27001 position
We are not ISO 27001 certified. A certificate comes from an accredited certification body after a two stage audit, and we have not been through that audit. What we operate is the control base and the risk method that the standard requires, and we are building out the management system elements that remain.
Areas assessed
10
Operating and evidenced
4
Areas with an open gap
6
How this relates to our SOC 2 work
ISO 27001 uses the same control base through Annex A, so the work is shared rather than duplicated. The difference is that ISO also requires a management system: a scope statement, a risk method, an internal audit program, and a management review. We hold the control work and the risk method today, and the internal audit program and management review are the remaining build.
Management system clauses
Clauses 4 and 5. Management system
Being strengthenedThe scope of the management system is defined, and leadership demonstrates commitment through an approved policy and assigned roles.
Evidence an assessor would request. The scope statement, the information security policy, and the record of assigned responsibilities.
Open gap. The scope statement and policy exist. They need formal versioning and an approval record with dates.
Clause 6. Planning
Being strengthenedRisks and opportunities are assessed against a defined method, with a treatment plan and a statement of applicability.
Evidence an assessor would request. The risk method, the risk register, the treatment plan, and the statement of applicability.
Open gap. The statement of applicability covering all Annex A controls with a justification for each has not been written yet.
Clause 7. Support
Operating and evidencedResources, competence, awareness, communication, and documented information are managed.
Evidence an assessor would request. Competence records, the training plan, awareness activity, and document version control.
Clause 8. Operation
Operating and evidencedThe organization plans, implements, and controls the processes needed to meet its requirements.
Evidence an assessor would request. Operating procedures, records that they ran, and the results.
Clause 9. Performance evaluation
Being strengthenedMonitoring, measurement, internal audit, and management review are performed.
Evidence an assessor would request. The internal audit program covering the whole system over a cycle, and management review outputs.
Open gap. A documented internal audit program with a schedule across the full cycle is the main outstanding item.
Clause 10. Improvement
Being strengthenedNonconformities are corrected, and the management system is continually improved.
Evidence an assessor would request. The nonconformity log, root cause analysis, and evidence that corrections held.
Open gap. Corrections are recorded against incidents. A single nonconformity log covering control failures as well is being built.
Annex A control groups
A.5. Annex A organisational controls
Operating and evidencedPolicies, roles, supplier relationships, and continuity of information security are governed.
Evidence an assessor would request. The policy set, supplier agreements with security terms, and the incident and continuity procedures.
A.6. Annex A people controls
Operating and evidencedScreening, terms of employment, awareness, discipline, and exit are managed for security.
Evidence an assessor would request. Screening records, signed terms, awareness evidence, and dated exit records.
A.7. Annex A physical controls
Being strengthenedPhysical areas, equipment, and media are protected.
Evidence an assessor would request. Clear desk and clear screen rules, device encryption evidence, and secure disposal records.
Open gap. We work remotely, so the physical controls apply to home working and devices. The home working standard needs writing down rather than assuming.
A.8. Annex A technological controls
Being strengthenedEndpoints, access, cryptography, logging, monitoring, vulnerability management, and secure development are controlled.
Evidence an assessor would request. Configuration baselines, encryption settings, log retention, alerting, and scan and remediation records.
Open gap. Logging and alerting on our own estate is the open item, and it is already phase two work.
If your process requires a certificate
Tell us at the start. We will not claim an equivalence an assessor would reject. What we can offer instead is our control register with dated evidence, a completed questionnaire answered from that register, and a walkthrough with the person who operates the control.