ISO/IEC Certification Audits and Assessments; we are ready when you are! Call +1 (888) 896-7580 today.
The professionals at Lazarus Alliance are completely committed to you and your business’ ISO 27000 certification audit (27001, 27017, 27018, and 27701) ISO 9000 certification audit (9001 and 90003), and others. Regardless of whether you represent the private sector or the public sector, we stand ready to partner with your organizations. Our competition may want to keep you and your employees in the dark where security, risk, privacy, and governance are concerned, hoping to conceal their methodology and expertise. We don’t prescribe to that philosophy. We believe the best approach is transparent and built on a partnership developed on trust and credibility, creating sustainability within your organization.
ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in ISO/IEC 27001 are generic and are intended to be applicable to all organizations, regardless of type, size or nature.
ISO/IEC 27017 gives guidelines for information security controls applicable to the provision and use of cloud services by providing additional implementation guidance for relevant controls specified in ISO/IEC 27002 and additional controls with implementation guidance that specifically relate to cloud services. ISO/IEC 27017 provides controls and implementation guidance for both cloud service providers and cloud service customers.
Comprehensive ISO/IEC Pre-Assessment and Certification Audit Services
Frequently Asked Questions
What is ISO certification?
ISO certification is a third-party validation from an accredited certification body confirming that an organization meets the requirements of an International Organization for Standardization (ISO) standard, such as ISO 9001 (quality management) or ISO 27001 (information security). It demonstrates adherence to global best practices.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001:2022 specifies ISMS requirements and is certifiable. ISO 27002:2022 provides implementation guidance for the 93 Annex A controls but is not certifiable.
What is the ISO 27001 certification process?
The ISO 27001 certification process includes:
- Define ISMS scope and objectives.
- Conduct a risk assessment (ISO 31000 or 27005).
- Implement Annex A controls.
- Document policies and perform internal audits.
- Engage an accredited certification body for Stage 1 (documentation) and Stage 2 (implementation) audits.
- Address findings for certification.
How long does it take to get ISO 27001 certified?
ISO 27001 certification takes 6-18 months, based on ISMS scope, risk assessment complexity, and control implementation. Small organizations may achieve it in 6-9 months, larger ones in 12-18 months.
How long does it take to get ISO 9001 certified?
ISO 9001 certification takes 3-12 months, depending on organization size, existing QMS maturity, and remediation needs. Small businesses may take 3-6 months, larger firms 6-12 months.
How do I get ISO 27001 certified?
To achieve ISO 27001 certification:
-
- Define ISMS scope and conduct a risk assessment (ISO 27005).
- Implement 93 Annex A controls (2022 version).
- Document policies and asset register.
- Conduct internal audits and management reviews.
- Hire an accredited certification body for Stage 1 and Stage 2 audits.
- Maintain continual improvement.
Contact us for more information
What to Expect
Differentiate yourself from your competitors by providing independent verification that your information security management system has met the requirements of this globally-recognized information security standard.
Certificate Directory
Lazarus Alliance maintains a public register for all certificates issued by the certifying body. The purpose of this registry is to enable third parties, who are in receipt of a certificate, to validate the legitimacy and currency of the document without having to contact a Lazarus Alliance representative.