ITVC GLOBAL · BUSINESS SERVICES
For current implementation, consider ISO/IEC 27001:2022 with Amendment 1:2024. System certification does not guarantee that every information security incident will be prevented.
ISO/IEC 27001:2022 and its 2024 amendment
ISO/IEC 27001 certification involves an independent assessment of the organization’s ISMS by a certification body. Initial certification normally includes Stage 1 and Stage 2 audits, followed by a separate certification decision. The preparation, audit and follow-up activities are outlined below.
Preparation and Stage 1: after agreeing the scope and certification arrangements, the certification body reviews relevant ISMS documentation and readiness for Stage 2. This may include policies, risk assessment, the Statement of Applicability, internal audits and management review. An optional preliminary assessment is not a substitute for Stage 1.
Stage 2: auditors assess implementation and effectiveness within the agreed scope. They examine policies, requirements, procedures and evidence that documented arrangements operate in practice; document review alone is insufficient.
Evidence can include access authorization records, management meeting records approving policies, interviews and direct observation of ISMS processes.
Audit reporting and follow-up: findings are reported to management. The certification body classifies findings under its applicable rules. Typical categories include:
Observation or opportunity for improvement: a matter worth considering, distinguished from a failure to meet a requirement.
Minor nonconformity: a failure to meet a requirement that does not undermine the system’s overall ability to achieve intended results. The organization must address it through correction, cause analysis and corrective action as applicable. The certification body specifies the required response, verification and deadlines; acceptance of an action plan does not remove the obligation to implement it.
Major nonconformity: a failure affecting the system’s ability to achieve intended results. Certification cannot be granted until the required correction and corrective action have been reviewed and their effectiveness verified by the certification body. Additional audit activity may be necessary. Auditors identify the finding; they do not provide the organization’s implementation consultancy.
After initial certification, surveillance audits monitor continued conformity. Certification generally follows a three-year cycle, with recertification before the certificate expires, subject to the certification body’s programme and continued compliance.
BSI — ISO 27001 certification journey
ITVC GLOBAL · SERVICE ENQUIRIES
Share your requirements and preferred timing. ITVC will review your enquiry and discuss a suitable service scope.
Hotline: 0914 564 579
Ho Chi Minh City: 0859 553 986
Email: itvc.haiphong@itvc-global.com
Head office: 6th Floor, 22 Ly Tu Trong, Hong Bang Ward, Hai Phong, Vietnam.
Copyright © 2014 ICTV. All Rights Reserved.
tư vấn iso, tu van iso, kiểm toán năng lượng, kiem toan nang luong