- Home
- Certification
- Standards
- Manage information-security risk as a business system.
Manage information-security risk as a business system.
ISO 27001:2022 — Information Security Management. Security controls chosen from a list, without a risk assessment behind them, protect the wrong things well. ISO 27001 examines whether the controls in place are the ones the organisation's own risk assessment called for.
Certification programme — accreditation is not claimed on this page.
Each standard page states its accreditation status exactly as it appears in the current official documents of Global Energy Up. The phrase “accredited certification” and any accreditation symbol are used only where the standard and the activity fall inside the published official scope.
Field status: a current accreditation document for this programme has not yet been received in a publishable form. The programme is therefore presented here without an accreditation claim — and the absence of evidence is not a conclusion in either direction.
Three specific situations.
- A supplier facing security due-diligence questionnaires from enterprise customers.
- An organisation processing personal or commercially sensitive data at scale.
- A business after an incident, needing to demonstrate a managed response.

What has to be evidenced.
- Context, scope and the statement of applicability
- Information-security risk assessment and treatment
- Controls actually implemented, against those declared
- Competence, awareness and communication
- Operational planning and change control
- Incident management and lessons learned
- Performance evaluation, internal audit and improvement
Not a one-time inspection.
Application and review
System scope, sites, activities, effective personnel count and outsourced processes.
Global Energy UpStage 1
System readiness: documentation, internal audit, management review and site arrangements.
AuditStage 2
Implementation and effectiveness in practice, against evidence.
AuditCorrection and corrective action
Nonconformities addressed and their effectiveness examined.
ClientIndependent technical review
Performed by someone who took no part in the audit.
Independent reviewerCertification decision
Taken by authorised personnel who did not participate in the audit.
Authorised decisionSurveillance
Periodic audits confirming continued conformity during the cycle.
AnnualRecertification
Full review of continued effectiveness before renewal after three years.
Every 3 years
The limit, plainly.
Certification does not mean your product conforms and does not mean your performance is excellent. It means your management system met the requirements of the standard at the assessment date, within the scope and sites shown on the certificate.
Management-system certification services are delivered by Global Energy Up. Energy Up International does not issue management-system certificates.
Act
Describe the claim — not the service.
Tell us what must be relied on, who will rely on it and by what date. We will confirm the correct programme, evidence requirement and responsible entity — or tell you it is outside our scope.
