ISO/IEC 27001 specifies an information security management system, or ISMS. Certification is granted by an accredited certification body after an external audit, and it is renewed through ongoing audits.
The standard text is sold by ISO, so this hub summarizes the path and does not reproduce it. Buy the standard before you start, because auditors work from it.
The path to certification
- Set the scope and contextDecide what the ISMS covers before you buy anything.
- Choose the business units, locations, systems, and services in scope.
- Identify the interested parties and what they expect, including customers, regulators, and staff.
- A narrow, honest scope is faster and cheaper, and it can expand later.
- Get leadership commitmentThe standard puts responsibility on top management.
- Set an information security policy and objectives that leadership approves.
- Assign roles and responsibilities, and provide resources.
- Plan how security performance will be reviewed.
- Run the risk assessmentAuditors check that your choices follow from your risks.
- Define a method, then identify assets, threats, and vulnerabilities.
- Rate the risks, decide on treatment, and have owners accept the residual risk.
- Keep the results, because they are core audit evidence.
- Write the Statement of ApplicabilityIt lists the controls you selected, why, and their status.
- Go through the control catalog and mark each control applicable or not, with a reason.
- Link each applicable control to the risk it treats.
- Implement and documentBuild the controls and the records that prove them.
- Implement the selected controls, from access control and logging to supplier management and incident handling.
- Keep documentation proportionate. Auditors want evidence that the controls operate, not a library of policy.
- Train staff on the parts of the ISMS that affect them.
- Audit and review internallyBoth are required before the certification audit.
- Run an internal audit of the whole scope, and fix the findings.
- Hold a management review that covers results, risks, and improvement actions.
- Pass the certification auditChoose an accredited certification body.
- The certification body audits in stages, reviewing your documentation first and then the operation of the system.
- Fix any nonconformities, and the body issues the certificate.
- Expect surveillance audits during the certificate cycle and a recertification audit at the end.
- Ask each body about its accreditation and its experience in your sector.
General information, not legal or professional advice. Official documents change, so confirm details with the linked sources before you act.
// firms
Canadian firms that work on this
Firms whose own websites name ISO 27001 or list closely related services. A listing is not an endorsement.
3Tenets Consulting
Penetration testing, AI and LLM security, threat and risk assessment, incident resilience, privacy impact assessment and governance/vCISO services.
- Pen testing
- AppSec
- GRC advisory
- IR and forensics
- Privacy
- NIST CSF
- CIS Controls
- ISO 27001
- MITRE ATT&CK
- OWASP
Appollon Inc.
Managed detection and response with 24/7 SOC monitoring, behavioural detection, active threat response and forensic investigation and remediation, aimed at gaming and tech companies in Quebec.
- MDR and SOC
- IR and forensics
- SOC 2
- ISO 27001
- Law 25
Canadian Cyber
Toronto firm offering ISO 27001 and SOC 2 consulting, internal audits, audit simulation workshops, virtual CISO services and CIS framework implementation.
- GRC advisory
- Audit and certification
- ISO 27001
- SOC 2
- CIS Controls
Cyberwall
Ten managed security services including 24/7 managed SOC, MDR, SIEM as a service, endpoint, identity and cloud security, plus consulting in incident response, penetration testing, compliance and privacy.
- MDR and SOC
- MSSP
- IR and forensics
- Pen testing
- GRC advisory
- +3
- SOC 2
- PIPEDA
- HIPAA
- PCI DSS
- ISO 27001
eSentire
24/7 managed detection and response and SOC service with digital forensics and incident response, response and remediation, and autonomous penetration testing and continuous threat exposure management.
- MDR and SOC
- IR and forensics
- Pen testing
- SOC 2
- ISO 27001
- MITRE ATT&CK
EthiSecure Services Inc.
Quebec firm offering audit and compliance, security consulting and advising (architecture, vulnerability assessment, risk analysis, policies, virtual CISO and privacy officer roles) and training and certification.
- Audit and certification
- GRC advisory
- Architecture
- Vulnerability mgmt
- Privacy
- ISO 27001
- PCI DSS
- HIPAA
- SOC 2
// faq
Common questions
How long does certification take?
It depends on scope, existing maturity, and how much time your people have. Organizations with a narrow scope and good existing controls move faster. Be wary of anyone who promises a fixed timeline before they understand your scope.
Do we need a consultant?
No, but many organizations use one to speed up the first pass. Choose an adviser who teaches your people to run the ISMS, because you will operate it after they leave.
Is ISO 27001 the same as SOC 2?
No. ISO 27001 certifies a management system. SOC 2 is an auditor’s attestation on controls against the Trust Services Criteria. Customers sometimes accept either, so ask which one they want.
// more hubs
Keep going
Windows hardening
An ordered path to harden Windows clients and servers, with the official baselines and documentation to build from.
CPCSC: Canadian Program for Cyber Security Certification
What the program is, how its three levels work, the 13 Level 1 controls, and how to prepare, drawn from the official government pages.
Small business security baseline
A 90-day plan built on the Canadian Centre for Cyber Security baseline controls for small and medium organizations.