ISO27001:2022 – FAQs
ISO27001-FAQ – All ISO27001 help you need in one place
First, our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon). The book gives you the structure you need to implement ISO27001, and the tools help you do it! What could be easier?
Still have questions? That’s fine… the purpose of this ISO 27001 – FAQ is to answer questions we get asked, and some of the myths we want to dispel.
What is ISO27001:2022
ISO27001 is the internationally recognised standard for implementing an Information Security Management System (ISMS). Picture it as a map of the universe, with directions, and stop-off points that will ultimately lead you to your destination (that big shiny certificate on the wall, and a trusted and safer business).
It’s made up of two parts; The Information Security Management System (ISMS) and the Annex A controls. There are currently 93 controls in the Annex A, and these are separated into four (4) themes;
- Organisational Controls
- People Controls
- Physical Controls
- Technical Controls
This is very closely aligned to the ‘People, Process, Technology’ terminology that you may have come across. But it clearly shows that ISO27001 is about more than just IT.
What is ISO27002:2022?
Great question… There are a number of guidance documents within the ISO27000 ‘family’. ISO27002 is just one of them. It provides detailed explanations on what you should consider when implementing the 93 controls of Annex A (contained within ISO27001).
The important thing to remember is that ISO27001 talks about what you shall put in place, and ISO27002 talks about what you should put in place. It is guidance. It is not a standard and therefore you cannot be certified against ISO27002.
Who needs ISO27001?
No matter if you’re handling personal information, financial data, or commercial data, it’s clearly important and valuable to you (and your clients). Understanding how to protect it is therefore critical to you and your organisation, and ISO27001 is your best approach to implementing a system that helps you protect it.
Consultants Like Us would of course recommend that every organisation has implemented this standard, and it’s not just because we help people achieve it. It’s because we believe in what it is there to do – make us all safer and more secure.
In truth however it is NOT mandatory, and is is therefore completely discretionary. So the real question is do YOU need ISO27001?
Ask yourself these questions;
- Are clients asking for it?
- Are you spending money on security without knowing why?
- Are you looking to scale your business?
If your answer to any of the above is YES, then you need it.
ISO27001 offers a road map to a more trusted and secure business. This is why we all need it.
Do I need to be ‘certified’ to ISO27001?
In a word, no. But if you’re doing the work to align to the standard, then why wouldn’t you do the test at the end? It’s like learning to drive, but never getting the licence at the end!
Getting ISO27001 certified is like donning a superhero cape for your business. It screams to your clients, “I’m serious about keeping your secrets safe!”
But the process of aligning and achieving ISO27001 has a plethora of goldmine of benefits too!
- It helps you become more efficient and effective at managing security risks
- It demonstrates to your clients and others that you take data security seriously
- It helps you land bigger deals and win tenders
- It improves the procurement process
- It saves you money, by focusing on key areas of (security) risk
- It aligns with other standards (like ISO9001) so if you have them, it’s even easier to work with!
- It helps you demonstrate compliance with national and international data protection laws (like the EU GDPR)
How do I become ISO27001:2022 certified?
If you decide to take the plunge and want to go through the process, then follow these steps are you’ll be well on your way to achieve certification.
- Buy the ISO27001 standard
- Buy the ISO27002 guidance
- Read them (both)
- Complete a gap analysis between where you are, and what is required in ISO27001
- Create a ‘to do’ list
- Identify your most important assets (physical and virtual)
- Identify the risks to these assets
- Action your ‘To Do’ list (to protect these assets)
- Sign-up a Certification body (someone like Approachable Certification) for your Stage 1 and 2 audits
- Agree dates for Stage 1
- Agree dates for Stage 2
- Run your external audits
- Celebrate with a big mug of Yorkshire tea (there is no other tea available).
- There you are! It’s that easy.
- Of course there are tasks here to be completed, like conducting internal audits, management reviews and training. But that’s easy right?
Consultants Like us have a simple four step process that takes all the above into account;
- Discover – Where we learn all about you and your business
- Design – Where we design the ISMS around you
- Develop – We develop the ISMS so it firs you perfectly.
- Deploy – We implement the standard so it works FOR you, not against you.
Remember that we provide ‘Compliance without Complexity’ (anyone can make something complicated). We want to make security easy for you and your business.
Do I need Consultants to do this?
The simple answer is, no, you might not need Consultants Like Us.
You could do this on your own. We don’t know what skills or experience you have. But if you have the time and competency to implement ISO27001, then go for it!
But before you rush off to buy a policy pack, why not use ChatGPT and ask it to create your policies for you.
Can I use ChatGPT to create my ISMS?
If you’re looking to do this on your own, then let us save you a few hundred pounds. Just remember NOT to paste any company confidential information into ChatGPT, but try these prompts and see what happens.
First, start by telling it how to act.
“Act as an ISO27001 expert, who understands the [Insert your industry here]. Write the following in the ‘first person’.” (this is important so that it talks about ‘we’ and ‘ours’).
Now tell it what you want;
“Write an Information Security Policy that includes a commitment to Continuous improvement. Write it in a friendly and conversational manner.”
Now go on and tell it what other ISO27001 policies you need. Such as
“Now write an Acceptable Use Policy, a back-up policy, a policy on [insert policies]”
Once you have all the ISO27001 policies, ask it to create a Risk Register
“Now create a risk register in a table, and provide risks associated with [your industry]”
Need an internal audit plan? No problem.
“Create an Internal audit plan that focuses on the Annex A controls of ISO27001:2022”
Carry on in this way until you have all the documents you need.
How much does it cost to be Certified?
As a wise man once said to me; If you measure everything by cost, you won’t see the value in anything.
But lets get serious; The answer is always “it depends” right? Well, sort of. Let me try and break it down for you, and show you some typical, tangible costs;
- Do it yourself – Using ChatGPT – £0
- Do it yourself – Using templates – £100 – £800
- Using Consultants Like Us – £3,500 – £15,000
- Certification Body (stage 1 and stage 2) – £4,000 – £7,000
So you can see there is a big leap from doing it yourself and bringing in a professional.
But that’s true of anything, right?
Want to fit a new kitchen? Sure… Do it yourself and costs are low. Bring in an expert and suddenly it’s a lot more expensive.
The questions you have to ask yourself are;
- What value do you place on your time?
- How quickly do you want this done?
- What assurances do you need that you will be certified AND more secure?
Do your research, but make sure you factor in the cost of your time and what your true goal is.
How long does it take to become Certified?
This goes back to the previous question… it depends! In our experience it can take anything between three (3) and six (6) months. It depends on the size of your business, the scope of the ISMS, how much time you are willing to devote to the process, and the certification body you go with.
Certification Bodies (CB) are very busy, and we’re seeing a four (4) to six (6) month wait time for stage 1 and stage 2 audits to be completed. Yes, some are quicker but our advice is to book a CB as soon as you can. It’s like booking a holiday! It gives you something to aim for!
What is the ISO27001 Certification Process?
There are essentially three (3) stages that you will go through with the Certification Body;
- Stage 1 – ISO27001 Audit of the ISMS
- Stage 2 – ISO27001 Evidence Audit
- Annual Surveillance Audit
Your Stage 1 audit is intended to check that you have all the mandatory records and documentation in place.
Your Stage 2 audit will check that you are doing everything you said you would do. For example, in stage 1 you need an “audit plan”, which is a schedule of audits you’ll conduct. Stage 2 will need to see evidence audits are being completed.
Your annual surveillance audit is in place to ensure you’ve continued to do the things you said you were going to do!
Where can I get more questions answered?
We’ll keep adding to this ‘FAQ’ list, so keep on sending in your questions and I’ll do my best to answer them for you!
If you would like to join our FREE Weekly ISO27001 drop-in sessions, then get in touch.
If you’d like to sign-up to our Newsletter, please click here.
