ISACA Now Blog

Knowledge & Insights > ISACA Now > Posts > Vendor Selection for ISO 27001:2013 Certification

Vendor Selection for ISO 27001:2013 Certification

K. Harisaiprasad, CISA, APP, ISO 27001 Lead Auditor, Associate Consultant, Mahindra SSG, India
| Posted at 2:44 PM by ISACA News | Category: Certification | Permalink | Email this Post | Comments (3)

K. HarisaiprasadThe Information Security Management Systems Certification (ISO 27001:2013) helps organizations prove they are managing the security of clients’ and stakeholders’ information, and can generate the need for three types of vendors: certification body, internal audit and implementation.

The certification body (CB) is an organization accredited by a recognized accrediting body (UKAS, ANAB, etc.,) for its competence to audit and issue certification confirming that an organization’s processes meets the requirements of the ISO 27001:2013 standard. The certification is valid for three years with a successful annual audit and no major non-conformance for the duration of the certification. Organizations that are proceeding with certification for the first time have to undergo Stage I and Stage II audits from a certification body. The stage I audit is a preliminary documentation audit in which policies, procedures, risks, objectives, etc., are audited against the standard, and readiness for Stage II is assessed. In stage II, audit implementation and effectiveness of standards are evaluated. Certification cannot be done in-house, so the CB vendor needs to be on-boarded. Apart from cost and business requirements, the organization has to ensure that it gets certified from an accredited CB.

Internal auditor audits are based on ISO 27001 standards, which is done prior to external audit (certification body stage I and stage II audit). Internal audits can be done by in-house personnel or by a vendor. If organizations are deploying in-house personnel, they have to ensure that internal audits are done independently and impartially (i.e., the auditor shall not audit his or her own work). Internal auditors that are selected should be competent with ISO 27001 Lead Auditor certification, preferably by the International Register of Certificated Auditors with a CISA or similar certification. The experience of the auditor should be at least three years. A CV and project sign-off statement from previous clients can help evaluate competency.

Implementation then involves doing a risk assessment, training, formulating policies and procedures, creating awareness training, analyzing metrics, conducting a management review meeting, etc. This activity can be performed either by in-house personnel or by a vendor. The implementation should be done by a competent ISO 27001 Lead Implementer/Lead Auditor certified preferably by IRCA, with experience of three years post-certification along with CISA, CISM, CISSP or similar certification. Again, a CV and project sign-off statement from previous clients of the implementer can be helpful.

The time required for these three activities varies, but generally, the assignment would be for three years. A point of contact who has knowledge of the entire certification cycle is recommended. Activities of the certification body and internal auditor involve preparing the audit schedule, conducting audits, audit reporting and approving a Corrective Action Plan (CAP). CAP is the plan one submits to the auditor mentioning how the identified gaps during the audit would be closed. The duration of the audit depends on the number of people, number of locations, number of processes/departments involved, etc.

Implementation is generally of a much longer duration than the audits, as it involves multiple activities being performed in parallel. Inputs of the implementer are important during audits, and they need to be deployed in the organization for a few months to complete the certification process. For an organization that has a single location and about 100 people, the certification process would typically take three-to-six months to complete.


Consultant - Audit

Assalamu alikum,

Is doing consultancy and audit allowed
Feroz349 at 7/15/2019 6:23 AM

Relevant to ISO 27001:2013

Assalamu alikum,

Among the following CISA, CISM, CISSP, which is more nearest to ISO 27001:2013
Feroz349 at 7/15/2019 6:34 AM

Reply to comments

Dear Feroz,

Alikum Asslamu, for your first query consultancy and audit allowed by the same vendor provided these two activities are done by different people as the standard mandates impartial and independence.

For the second query, for Auditing CISA is most relevant and for Implementation CISA and CISSP is most relevant
Harisaiprasad585 at 10/11/2019 12:00 AM
You must be logged in and a member to post a comment to this blog.