1
Planning and Scoping
Understand the mission, purpose, and objective of the project, identify key stakeholders and resources, define priorities, establish a timeline, define the scope of the project, and establish expectations.
2
Risk Assessment and Gap Analysis
Conduct a risk assessment to determine which controls are required, and a gap analysis to determine whether required controls exist. Identify the current state, define the desired state, and develop a roadmap and action plan based on the results of both assessments.
3
Implemention
Implementation of required controls in accordance with the roadmap and action plan established in step 2. This includes taking clauses 4-10 into account, addressing gaps, developing policies and procedures, training employees, and activating the ISMS.
4
Operation and
Allow the implementation to perform its intended purpose. Monitor, log, track, collect evidence, document, test the controls, perform another risk and gap assessment of the ISMS against the target state objective, and simulate audit activities.
5
Certification
Engage an ISO 27001 auditor to audit the ISMS. There are two audit stages (design review and certification audit) which then conclude with official certification. BitSpartan can be on-site to support the audit.
6
Maintenance
This is primarily step 4 with the addition of continuous improvement to the ISMS. Certification has a validity period of 3 years. Surveillance audits occur in years two and three, and re-certification (step 5) occurs prior to the end of the third year.
Timeline
The following is a typical timeline for obtaining ISO 27001 certification. This information is provided to give you a sense of how long it might take on average. Numerous factors can cause it to be shorter or longer. Existing controls, the client's resources, the client's security culture, the complexity of the ISMS, the scope of the system, the budget, the client's goals, objectives, and requirements. Additionally, an organization may require the process to be expedited for a variety of reasons, requiring additional resources on both sides to reduce the time required to achieve certification. These are just a few examples of factors that affect the timeline.
-
Small Business
(4-6 months)
Average timeline for organization between 2-60 employees
-
Medium Business
(6-12 months)
Average timeline for organization between 60-120 employees
-
Large Business
(12-24 months)
Average timeline for organization between 120+ employees