The international standard for an information security management system, and the certification most often requested by enterprise customers and procurement teams.
Any organisation that wants a recognised, auditable statement that it manages information security as a system rather than as a collection of tools. It is voluntary, but in practice it is frequently mandatory: it is the certification enterprise procurement asks for by name.
The work divides into scoping, gap closure and evidence. Scoping is where most programmes are won or lost: a scope drawn too wide creates years of work, and one drawn too narrow fails to satisfy the customer who asked for the certificate. Gap closure addresses what the assessment found. Evidence is the part organisations underestimate, because an auditor tests whether a control operated throughout the period, not whether a policy exists today.
A certificate issued by an accredited certification body, typically valid for three years with annual surveillance audits. The certificate is issued by the certification body and not by us.
SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.
Control mappings exist between this framework and others in the library, so evidence gathered here may support work elsewhere. Mappings are published as draft, and a mapping shows a relationship rather than satisfied coverage. An auditor decides whether the evidence answers the requirement.