SYSTEM CERTIFICATION SERVICES
Need ISO 27001 Certification for Your Business?
Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.
FREQUENTLY ASKED QUESTIONS
Frequently Asked Questions
Yes. ISO 27001 does not require an organization to replace all of its technology. Existing systems and processes can be assessed, improved and controlled according to the organization's information-security risks.
No. An organization can define an appropriate ISMS scope based on its activities, locations, information, services, technology and business objectives.
Yes, where the proposed scope is clearly defined and appropriate. The organization should identify the people, processes, information and technology included within that boundary.
Yes. A SaaS platform or cloud service can form part of an ISMS scope when its information, processes, systems, responsibilities and supporting activities are properly defined.
Consider business activities, locations, information assets, systems, employees, suppliers, customers, legal obligations and the services or processes that need protection.
Yes. Multiple offices can be included when their activities and information-security responsibilities are appropriately covered by the defined ISMS scope.
Yes. Remote working can be addressed through suitable access management, device controls, authentication, information-handling rules and other measures based on identified risks.
Yes, if employees or contractors use personal devices to access organizational information. The organization should establish appropriate controls based on the associated risks.
Organizations should ensure that people whose work affects information security are appropriately aware of their responsibilities and have the competence needed for their roles.
Training records, induction programmes, awareness activities, assessments, simulated exercises and other documented evidence can demonstrate how security awareness is managed.
No. ISO 27001 does not prescribe a particular software brand. Security solutions should be selected according to the organization's risks, technology environment and business needs.
ISO 27001 does not impose one identical MFA configuration on every organization. Authentication controls should be selected according to access risks and the sensitivity of the systems and information involved.
Privileged access should be appropriately authorized, restricted, monitored and reviewed according to risk. Organizations should avoid unnecessary administrative privileges.
Yes. Periodic access reviews can help confirm that users retain only the permissions appropriate to their current responsibilities.
The organization should have a controlled process for removing or adjusting access when employment or responsibilities end or change.
Yes. Third-party access can be included when external organizations interact with systems, information or services within the ISMS scope.
Yes. Contracts can establish relevant security responsibilities, confidentiality requirements, access conditions, incident obligations and other requirements appropriate to the supplier relationship.
Yes. Outsourced services can affect information-security risks and should be considered when assessing suppliers and defining appropriate controls.
Yes. If the provider supports systems, processes or information within the ISMS scope, its activities and associated risks should be considered.
SaaS organizations can use an ISMS to manage risks involving customer information, applications, infrastructure, access, development, suppliers, incidents and operational processes.
Yes. Software companies can apply an ISMS to source code, development environments, repositories, access rights, change management, customer information and supporting infrastructure.
Yes. Where source code is an information asset within the ISMS scope, related confidentiality, integrity, access and change-management risks can be addressed.
Yes. API-related risks can be included where APIs form part of systems or services within the ISMS scope. Appropriate controls should be selected according to the identified risks.
Yes. Mobile applications can be included when they process information or provide access to systems covered by the defined ISMS scope.
Yes. Data-centre environments can address risks involving physical security, infrastructure, access, availability, equipment and environmental conditions within the relevant scope.
Yes. Information security is not limited to networks and software. Physical access, facilities, equipment and environmental risks can also be relevant.
Yes. Physical information can fall within the ISMS when it is relevant to the organization's information-security objectives and defined scope.
Yes. Employee information can be treated as an information asset and protected according to its sensitivity and applicable legal, contractual and organizational requirements.
Yes. Customer information can be included in the organization's information-security risk assessment and protected through controls appropriate to its sensitivity and use.
No. ISO 27001 establishes an information security management system, while ISO 27701 focuses on privacy information management. The two can complement each other.
Yes. Organizations that manage both information-security and privacy risks may integrate the two management systems where appropriate.
It can provide a structured framework for managing information-security risks, but ISO 27001 certification should not be treated as automatic compliance with every UAE privacy or data-protection requirement.
It can support information-security aspects of privacy compliance, but ISO 27001 certification alone does not demonstrate complete GDPR compliance.
Business continuity and resilience can be relevant where disruption creates information-security risks. The specific arrangements should reflect the organization's circumstances and risk assessment.
Yes. Disaster recovery measures can support the availability and recovery of systems and information where those risks are relevant to the ISMS.
Yes. Backup processes can be included where they help protect information availability, integrity or recovery capability.
ISO 27001 does not prescribe one universal backup architecture. Backup arrangements should be designed according to business needs, recovery requirements and information-security risks.
Yes. Organizations can establish processes for reporting, assessing, responding to and learning from information-security incidents.
No. A security incident and an audit nonconformity are different matters. An incident may reveal a weakness, but its significance depends on the circumstances and the organization's processes.
Yes. Incident findings can help organizations identify weaknesses, reassess risks, improve controls and strengthen information-security practices.
Yes. An effective ISMS requires leadership, defined responsibilities, appropriate resources and management oversight rather than being treated solely as an IT project.
IT can have an important role, but information security commonly involves HR, procurement, legal, operations, management and suppliers. A cross-functional approach is generally more effective.
Yes. Organizations can integrate compatible management-system processes such as document control, internal audit, corrective action and management review while retaining the specific requirements of each standard.
Yes. Information security and business continuity can be managed together where their risks and processes overlap, while maintaining the distinct requirements of each standard.
A risk describes a potential event or situation that could affect information security. A control is a measure used to prevent, reduce, detect or manage that risk.
Yes, risk acceptance can be an appropriate treatment decision when it is justified, authorized and consistent with the organization's defined risk criteria.
No. Risk treatment may involve technical controls, policies, procedures, contractual measures, training, transfer, avoidance or informed acceptance, depending on the circumstances.
A risk register commonly records the risk, affected information or processes, likelihood and impact considerations, existing controls, treatment decisions, responsibilities and status.
It should reflect the organization's actual operations and meaningful information-security risks, with treatment decisions connected to practical controls, responsibilities and business priorities.
It should consider additional locations, systems, information, processes, employees, suppliers, risks, controls and resources that would become part of the expanded ISMS.
Scope changes may be possible, but significant changes should be discussed with the certification body because they can affect audit planning and the certified scope.
ISO currently identifies ISO/IEC 27001:2022 as the published third edition. ISO also lists ISO/IEC 27001:2022/Amd 1:2024, which introduced climate-action considerations to the management-system standards. Organizations should check the official ISO publication status when preparing their ISMS.