Home / Services / Certification Services / ISO/IEC 27001 Certification
GLI® Secure ISO/IEC 27001 Certification.
With cyber-crime on the rise and new threats constantly emerging, it can seem difficult or even impossible to manage cyber-risks. ISO/IEC 27001 helps organizations become risk-aware and proactively identify and address weaknesses.
Have your information security processes audited against the ISO 27001 standard and obtain certification from GLI Secure.
About the Standard
What is ISO/IEC 27001?
ISO/IEC 27001 is the world’s best-known standard for information security management systems (ISMS). It defines requirements an ISMS must meet.
The standard provides companies of any size and from all sectors of activity with guidance for establishing, implementing, maintaining and continually improving an information security management system.
Conformity with ISO/IEC 27001 means that an organization has put in place a system to manage risks related to the security of data owned or handled by the company, and that this system respects all the best practices and principles enshrined in this International Standard.
Ready to begin
Learn how certification builds trust with customers, partners, and regulators.
Certification
What does it mean to be certified?
Certification to ISO/IEC 27001 is one way to demonstrate to stakeholders and customers that you are committed and able to manage information securely and safely. Holding a certificate from an accredited conformity assessment body brings an additional layer of confidence, as an accreditation body has provided independent confirmation of the certification body’s competence.
Who is it for?
How long is it valid?
Companies that adopt the holistic approach described in ISO/IEC 27001 make sure information security is built into organizational processes, information systems and management controls. They gain efficiency and often emerge as leaders within their industries.
Requirements
What are the
requirements?
Certification requires organizations to implement the requirements found within the ISO/IEC 27001:2022 standard. Among them are Clause 4 – Context of the organization, Clause 5 – Leadership, Clause 6 – Planning, Clause 7 – Support, Clause 8 – Operation, Clause 9 – Performance Evaluation, Clause 10 – Improvement, and Annex A – Control objectives and controls.
Clauses 4–6
Context of the organization, Leadership, and Planning: understand your environment and build security into strategy.
Clauses 7–8
Support and Operation: resources, awareness, communication, and the day-to-day running of your ISMS.
Clauses 9–10
Performance Evaluation and Improvement: measure, audit, and continually improve your ISMS.
How does the certification process work?
Certification audits are performed through an onsite visit to the organization’s location. The audit consists of a documentation review against the standards requirements, with interviews being performed, observation of activities, as well as control testing to determine the operating effectiveness of the controls.
How GLI Secure approaches your audit
Certification Bodies (CBs) are public and private businesses accredited by the Standards Council of Canada (SCC) who have met the requirements of the SCC. CBs verify that businesses have met all the security controls for certification using assessment criteria developed by the standard’s issuing body, such as the International Organization for Standardization (ISO). GLI Secure is an accredited certification body. As Canada’s national accreditation body, the SCC rigorously assesses the experts who certify organizations.
To access the PDF with full details, please click on the links below:
Ready to simplify compliance and stay audit-ready year-round? With GLI Secure, compliance becomes clear, manageable, and strategic.
Gus Fritschie
SVP Information Security Services