Home > Services and Standards > Information Security Management ISO 27001
Information Security Management ISO 27001
ISO 27001 is the international standard for Information Security Management Systems (ISMS) based largely upon the previously adopted BS 7799 used commonly since 1995 for managing information security.
ISO 27001 provides the framework for a technology neutral, vendor-neutral management system that enables an organization to assure itself that its information security measures are effective. This includes the continued accessibility, confidentiality and integrity of its own information and that of its stakeholders as well as legal compliance.
Implementation of ISO 27001 is an ideal response to legal requirements and potential security threats such as:
- Vandalism / terrorism
- Fire
- Misuse
- Theft Viral attack
Whilst modern communication mediums mean that most ISMS systems are focused on ICT, ISO 27001 is equally applicable to other forms of information, such as paper records, images, and even conversations.
Who is ISO 27001 applicable to? ISO 27001 is applicable to any organization where the misuse, corruption, or loss of its business or customer information could result in major commercial prejudice.
NQA has registered organizations to ISO 27001 in sectors as diverse as storage and warehousing, secure destruction, telecommunications, advertising, financial outsourcing and software development.
What are the benefits of certification?
- Customer satisfaction by giving confidence that their personal information is protected and confidentiality upheld Business continuity through management of risk, legal compliance and vigilance of future security issues and concerns
- Legal compliance by understanding how statutory and regulatory requirements impact the organization and its customers
- Improved risk management through a systematic framework for ensuring customer records, financial information and intellectual property are protected from loss, theft and damage
- Proven business credentials through independent verification against recognized standards
- Ability to win more business particularly where procurement specifications require certification as a condition to supply
How to gain registration?
The process of registration follows three simple steps:
- Application for registration is made by completing the application questionnaire
- Assessment is undertaken by NQA the organization must be able to demonstrate that its ISMS has been fully operative for a minimum of three months and has been subject of a full cycle of internal audits
- Registration is granted by NQA and maintained by the organization.
- Maintenance is confirmed through a program of annual surveillance visits and a three yearly re-certification audit.
Download and print the ISO 27001 brochure.













