Certification to ISO/IEC 27001 Information Security Management

Keep your information confidential with a certified ISO/IEC 27001 system and show that you have information security risks under control. Compliance with world-class standards can help you win customer trust and new business opportunities.   



How to get certified to ISO/IEC 27001

ISO/IEC 27001 Information Security Management system certification should be hassle-free. You’ll be appointed a BSI Client Manager, a trusted expert with relevant industry experience to your business, who can guide you through the process.

The steps to ISO/IEC 27001 certification:

  • ISO/IEC 27001 gap analysis
    An optional service which takes place before your assessment visits. We’ll take a closer look at your existing information security management system and compare it with the requirements of the ISO/IEC 27001 standard. It’s a really cost effective way to check if there are any areas you need to work on before we carry out a formal assessment.

  • Formal assessment
    A two-stage process. First your BSI Client Manager will review your organization’s readiness for assessment by checking if the necessary ISO/IEC 27001 procedures and controls have been developed in your organization. We will share the details of our findings with you via our BSI Connect Portal, so that if we find gaps, you can close them.

    Next, if all the requirements are in place, we’ll assess the implementation of the procedures and controls within your organization to make sure that they are working effectively as required for certification of ISO/IEC 27001.

  • Certification and beyond 
    When you achieve certification you’ll receive your BSI ISO/IEC 27001 certificate which is valid for three years. Your BSI Client Manager will visit you regularly to make sure your system doesn’t just remain compliant, but it continually improves and adds value to your organization.

    Find out more about BSI Connect Portal


Are you confident your organization is secure and compliant with the APRA Prudential Standards?

All APRA-regulated entities need to prove they have the required capability, controls and internal audit assurance to confirm their information security resilience. Your organization may be secure, but your business partners and supply chain must also be compliant under CPS 231. BSI is able to assess your frameworks and policies and train your staff to help you meet the requirements of CPS 234 and CPS 231.



Your ISO/IEC 27001 certification journey

Explore our ISO/IEC 27001 certification journey – designed to help you at whatever stage you are at.