ISO 27001 certification demonstrates that the company has established a structured, risk-based framework for information security. It shows that the company takes a systematic approach to risk assessments, policies, responsibilities, security controls and continual improvement. 

The certification provides customers and business partners with evidence that information security is embedded in the organisation's management, processes, people and technology. It can also strengthen your position in tenders, supplier approval processes and international sales processes. 

When does it become relevant? 

ISO 27001 typically becomes relevant when: 

  • Customers or business partners request a recognised security certification 
  • Information security is critical to your services or business model 
  • You process sensitive, confidential or business-critical information 
  • Certification is a requirement in tenders or supplier approval processes
  • You want a common, scalable structure for risk management and information security 

The standard can be used by organisations of all sizes and across all industries and can be adapted to the company's specific risks, structure and needs. 

ISO 27001 or an ISAE or SOC report? 

ISO 27001 and ISAE or SOC reports meet different documentation needs. 

ISO 27001 is a certification of the company's information security management system against an international standard. 

ISAE 3000 and ISAE 3402 are international assurance standards, while SOC 1 and SOC 2 are US assurance report frameworks based on AICPA standards and criteria. They are used to provide assurance over specifically defined controls, systems, services or compliance areas. 

The services can complement each other. ISO 27001 provides a broad organisational framework for information security, while an ISAE or SOC report gives customers more detailed assurance regarding specific controls and their operation. 

 ISO 27001 CertificationISAE and SOC Reports
FocusFocuses on the company's overall management system and internal information security processes.Focuses on the controls and processes that support specific systems, services and customer deliverables, and documents whether the controls operate effectively in practice.
Audit cycle and testingThe certification follows a multi-year certification cycle in which annual surveillance audits do not necessarily involve full retesting of all areas.For each report issued, the auditor performs a new assurance engagement and tests the controls necessary to reach a conclusion on the full agreed scope for the period covered.
OutcomeThe outcome is a recognised certificate.The outcome is a detailed assurance report that can be shared with relevant customers and their auditors.
Documentation for the customerThe customer will typically see the certificate and the certified scope, but not a detailed control-by-control description of how the controls were tested and the results of the testing.Relevant customers and their auditors can receive the report and see which controls are covered, how they were tested and the results of the testing.
Particularly relevant forCompanies seeking to demonstrate the systematic management of their own information security.Service providers that need to give customers and their auditors assurance regarding the controls supporting the systems and services provided.

 

Which solution do you actually need? 

We help you determine whether your needs are best met by: 

  • ISO 27001 certification 
  • ISAE 3000 or ISAE 3402 
  • SOC 1 or SOC 2 
  • or a combination that can be used across customers and markets 

The aim is to select a solution that both strengthens your security organisation and meets the requirements that genuinely stand between you and your customers. 

How we approach an ISO 27001 engagement 

We make the path to certification clear and manageable, tailoring the process to your organisation and its current level of maturity. 

  1. Clarification and scope: We determine which services, systems, locations and organisational units are to be included. 
  2. GAP analysis: We assess your current framework against the requirements of ISO/IEC 27001:2022 and identify the most important gaps. 
  3. Preparation: We help establish or improve areas including risk assessment, policies, allocation of responsibilities, controls and the necessary documentation. 
  4. Audit preparation: We assess whether the management system has been implemented and operates in practice, so you are ready for the certification audit. 
  5. Certification and maintenance: Certification is performed by an independent certification body. The management system must then be maintained, evaluated and continually improved. 

 

 

Contact us about ISO 27001 

Contact us for an initial discussion about your needs, current level of maturity and a realistic path towards ISO 27001 certification. 

Kontakt os for en uforpligtende dialog om ISAE 3000 og compliance