Skip to content
AXIOS
ISO/IEC 27001:2022

ISO/IEC 27001 Certification

Prove your information security management system protects the data your business depends on.

Service overview

ISO/IEC 27001 defines the requirements for an information security management system (ISMS), including risk assessment, controls and a Statement of Applicability.

AXIOS reviews your ISMS documentation and implementation, verifying that controls are effective and proportionate to your information risk.

Who needs this service

  • Technology, cloud and data-handling organisations
  • Suppliers required to evidence security to customers
  • Any business holding sensitive or regulated information

Benefits

  • Independent assurance of information security controls
  • Reduced likelihood and impact of security incidents
  • Confidence for customers, partners and regulators
  • A structured response to evolving cyber risk

Watch: ISO/IEC 27001:2022 in brief

Video courtesy of ISO (iso.org).Read the official ISO/IEC 27001 standard on the ISO website (iso.org) →

What is ISO/IEC 27001?

ISO/IEC 27001 is the world's best-known standard for information security management systems (ISMS). It sets out the requirements for establishing, maintaining and continually improving information security through risk assessment and a set of controls.

The 2022 edition references the updated Annex A controls and requires a Statement of Applicability that justifies which controls you apply.

The structure of ISO/IEC 27001

Clause 1–3

Scope, references & terms

Introductory clauses defining the scope of the standard, normative references and key definitions.

Clause 4

Context of the organisation

Understand internal and external issues, the needs and expectations of interested parties, and the scope of the management system.

Clause 5

Leadership

Top-management commitment, an appropriate policy, and clearly assigned roles, responsibilities and authorities.

Clause 6

Planning

Address risks and opportunities, set measurable objectives and plan the actions and changes to achieve them.

Clause 7

Support

Provide the resources, competence, awareness, communication and documented information the system needs.

Clause 8

Operation

Plan and control the processes needed to meet information-security requirements and to implement the actions determined by information-security risk assessment and treatment.

Clause 9

Performance evaluation

Monitor, measure, analyse and evaluate; conduct internal audits and management reviews.

Clause 10

Improvement

Manage nonconformities and corrective action and continually improve the management system.

Benefits of certification

  • A risk-based, systematic approach to protecting information
  • Assurance for customers, partners and regulators
  • Reduced likelihood and impact of security incidents and breaches
  • A competitive edge in tenders that require ISO 27001
  • A foundation for privacy (ISO 27701) and other controls

Steps to certification

  1. 1

    Application & proposal

    You complete a quote request so AXIOS can understand your organisation and define the scope of assessment, then receive a tailored certification proposal.

  2. 2

    Two-stage initial audit

    A Stage 1 readiness review is followed by a Stage 2 assessment of your management system in operation. Your system should have run for at least three months with a management review and a full internal-audit cycle.

  3. 3

    Decision & certification

    After a successful Stage 2 and an independent certification decision, AXIOS issues your certificate — valid for three years and maintained through annual surveillance audits and a recertification audit in year three.

Frequently asked questions

What is the Statement of Applicability?

A controlled document listing the Annex A controls, whether each applies, and the justification — central to an ISO 27001 ISMS.

Is ISO 27001 only for IT companies?

No. Any organisation that handles sensitive or valuable information can benefit, regardless of sector or size.

How does risk assessment work?

You identify information-security risks, evaluate them, and select controls to treat them — then monitor and review continually.

How long is it valid?

Three years, with annual surveillance and a year-three recertification audit.

Official reference

Read the full ISO/IEC 27001 article and buy the standard on the International Organization for Standardization (ISO) website.

View ISO/IEC 27001 on iso.org →

Talk to AXIOS about ISO/IEC 27001 Certification

Our specialists will help you choose the right scope and plan a clear path to certification or assessment.

Contact us