ISO/IEC 27001:2022 certification program under way
CompliancePublished
We are establishing an information security management system (ISMS) to ISO/IEC 27001:2022, including Amendment 1:2024, and have applied to an accredited certification body for the certification audit.
Where we are
- Every one of the 93 Annex A controls is mapped to the policy, standard or procedure that will cover it.
- The ISMS documentation, from the top-level policies to the operating procedures, is being written.
- The scope is proposed and will be confirmed with the certification body.
What comes next
- Approve the policies and complete the risk assessment and the Statement of Applicability.
- Operate the ISMS and collect records, then run an internal audit and a management review.
- Undergo the certification audit, in two stages.
We will post an update in this feed at each milestone. The status on the Overview changes only when the certificate has been issued.