Skip to content
NUEXUS Technologies
International

ISO/IEC 27001

The international standard for an information security management system, and the one most often written into contracts as a supplier requirement.

NUEXUS delivers readiness, gap assessment, implementation support and evidence preparation. NUEXUS is not an accredited certification body and not an auditor, and cannot certify you, issue an attestation, or sign off on a result.

How it is organised

It certifies a management system, not a product

This is the point most first-time readers miss. ISO 27001 does not certify that your software is secure. It certifies that you run a repeatable system for identifying risk, deciding what to do about it, and checking that the decisions were carried out. An auditor is assessing your process, and your evidence that the process runs.

Risk assessment drives the controls, not the other way round

You are not asked to implement every control in the annex. You assess your risks, decide which controls treat them, and then justify anything you excluded in a Statement of Applicability. An implementation that starts by installing controls and works backwards to the risk is the one that struggles at audit.

Certification is a cycle, not an event

Certification involves a staged audit by an accredited body, followed by surveillance audits during the cycle and eventual recertification. The system has to still be running a year later, which is why an ISMS built purely for the audit date tends to fail the surveillance one.

What an assessor will ask to see

  • A defined ISMS scope, and a reason for that scope
  • The risk assessment and risk treatment plan, with owners
  • A Statement of Applicability with justifications for inclusions and exclusions
  • Policies that are approved, dated and actually circulated
  • Records of internal audit and of management review
  • Corrective actions raised, tracked and closed

Where it usually goes wrong

  • A scope drawn so wide that nothing inside it can be evidenced properly
  • Policies that exist as documents but that no one in the business has read
  • Risk assessments performed once at implementation and never revisited
  • No internal audit before the certification audit, so the first findings are the auditor's
  • Supplier and third-party risk treated as a form-filling exercise