Back to Services
Certifications & Standards

ISO 27001

ISO/IEC 27001 is the leading international standard for an Information Security Management System (ISMS) — and getting certified is a structured, multi-stage project.

Engagement typically starts with a gap assessment against the standard's Annex A controls, followed by ISMS design, a formal risk assessment and treatment plan, and implementation of the controls that came out as gaps. An internal audit is run before the certification body's two-stage external audit, and the certificate is maintained through annual surveillance audits across a three-year cycle.

See how LumiGRC handles ISO 27001

Get a Demo
3 Yr

Certification cycle

0%
Typical engagement profile
Technical Depth79%
Engagement Length74%
Ongoing Support Need74%
Issued & Enforced By

ISO/IEC

ISO/IEC 27001:2022

Key Points

  • Gap assessment against ISO 27001 Annex A controls
  • ISMS design plus a formal risk treatment plan
  • Internal audit ahead of the external certification audit
  • Ongoing support through the 3-year certification cycle