How to get certified against ISO 27001?
You have been implementing ISO 27001 Certification in Mumbai for quite a long time, invested quite a lot in education, consultancy and implementation of various controls. Now comes the auditor from a certification body will you pass the certification? It’s normal you can never know whether your information security management system has everything the certification body is asking for, but what it is exactly the auditor will be looking for? Stage 1- Document review: In this Audit and the author will look for the documented scope, description of the risk assessment methodology, information security management system policy and objectives, risk assessment report, risk treatment plan, statement of applicability, procedures for document control, corrective and preventive actions, and for internal audit. You will also have to document some of the controls from Annex A – inventory of assets, roles and responsibilities of employees, contractors and third party users, terms an...