Information Security Management audit context
  1. Home
  2. Certification
  3. Standards
  4. Manage information-security risk as a business system.

Manage information-security risk as a business system.

ISO 27001:2022 — Information Security Management. Security controls chosen from a list, without a risk assessment behind them, protect the wrong things well. ISO 27001 examines whether the controls in place are the ones the organisation's own risk assessment called for.

Standards applied
ISO 27001:2022
Accreditation status for this programme

Certification programme — accreditation is not claimed on this page.

Each standard page states its accreditation status exactly as it appears in the current official documents of Global Energy Up. The phrase “accredited certification” and any accreditation symbol are used only where the standard and the activity fall inside the published official scope.

Field status: a current accreditation document for this programme has not yet been received in a publishable form. The programme is therefore presented here without an accreditation claim — and the absence of evidence is not a conclusion in either direction.

Who typically applies

Three specific situations.

  • A supplier facing security due-diligence questionnaires from enterprise customers.
  • An organisation processing personal or commercially sensitive data at scale.
  • A business after an incident, needing to demonstrate a managed response.
Information Security Management audit context
What auditors examine

What has to be evidenced.

  • Context, scope and the statement of applicability
  • Information-security risk assessment and treatment
  • Controls actually implemented, against those declared
  • Competence, awareness and communication
  • Operational planning and change control
  • Incident management and lessons learned
  • Performance evaluation, internal audit and improvement
Certification cycle

Not a one-time inspection.

  1. Application and review

    System scope, sites, activities, effective personnel count and outsourced processes.

    Global Energy Up
  2. Stage 1

    System readiness: documentation, internal audit, management review and site arrangements.

    Audit
  3. Stage 2

    Implementation and effectiveness in practice, against evidence.

    Audit
  4. Correction and corrective action

    Nonconformities addressed and their effectiveness examined.

    Client
  5. Independent technical review

    Performed by someone who took no part in the audit.

    Independent reviewer
  6. Certification decision

    Taken by authorised personnel who did not participate in the audit.

    Authorised decision
  7. Surveillance

    Periodic audits confirming continued conformity during the cycle.

    Annual
  8. Recertification

    Full review of continued effectiveness before renewal after three years.

    Every 3 years
What the certificate does not mean

The limit, plainly.

Certification does not mean your product conforms and does not mean your performance is excellent. It means your management system met the requirements of the standard at the assessment date, within the scope and sites shown on the certificate.

Management-system certification services are delivered by Global Energy Up. Energy Up International does not issue management-system certificates.

Describe the claim — not the service.

Tell us what must be relied on, who will rely on it and by what date. We will confirm the correct programme, evidence requirement and responsible entity — or tell you it is outside our scope.