ISO 27001 certification for businesses trusted with data.
We build your information security management system to ISO/IEC 27001:2022, from scope and risk assessment to Statement of Applicability and certification audits, so you can meet client, government and tender security requirements.
Clients want proof their data is safe with you.
Government agencies, enterprise clients and head contractors increasingly require ISO 27001 before they'll share data or sign contracts. ISO 27001 shows your business identifies information security risks, applies the right controls and keeps improving, assessed by an independent certification body.
Who this is for
- IT service providers, managed service providers and software companies
- NDIS, aged care and health providers handling personal information
- Consultancies and contractors working with government data
- Any business whose clients, contracts or tenders require ISO 27001
What you get.
A scoped management system, documented controls and preparation for independent assessment.
- ISMS scope and context
- Gap assessment and implementation plan
- Information security policy, objectives, roles and ISMS procedures
- Risk assessment method, risk register and risk treatment plan
- Statement of Applicability covering all 93 Annex A controls
- Internal audit, management review and certification audit preparation
How it works.
Establish context and scope
We review the information and services in scope, business dependencies, relevant requirements and existing security arrangements.
Assess requirements and current state
We compare current practices and evidence with ISO 27001 requirements, then identify priority gaps for the agreed ISMS scope.
Assess and treat information security risks
We run your information security risk assessment, develop the treatment plan, assign responsibilities and record the controls selected for the scope.
Document and implement the ISMS
We develop the agreed policies and processes, support implementation and help organise evidence that the system is being operated.
Review readiness and prepare for audit
We support internal audit, management review and certification audit preparation.
Why Optimax.
Information security management built by governance, risk and compliance specialists.
- GRC specialists. Governance, risk and compliance is what we do every day, across ISO standards, government contracts and procurement.
- Management system experts. ISO 27001 is a management system first, and building certified management systems is our core work.
- Works with your IT provider. We handle the ISMS, policies and evidence; your IT provider implements the technical controls. We coordinate both.
- Combine with ISO 9001. Many clients certify to 27001 and 9001 together, sharing one set of management processes.
The practical details.
What does ISO 27001 cover?
It sets the requirements for an information security management system (ISMS): defining scope, assessing information security risks, applying controls from the 93 controls in Annex A, and reviewing and improving the system.
Does ISO 27001 certification guarantee that we will not have a security incident?
No. It shows you manage information security risk systematically and are independently assessed. You still need to operate and improve your controls.
Will you perform penetration testing or implement technical security tools?
No. We build and implement the management system. Where technical work is needed, such as penetration testing, firewall changes or endpoint security, we identify it in your risk treatment plan and coordinate with your IT provider.
Do we need to include our whole business in the ISMS?
No. The scope can cover specific services, locations or systems, as long as it's clearly defined and makes sense to your clients. We help you choose a scope that meets client requirements without over-complicating it.
How long does ISO 27001 certification take?
Typically 3–6 months, depending on scope and current arrangements. The certification body needs to see your controls operating before the Stage 2 audit.
Does Optimax Comply support ISO 27001?
Not currently. Optimax Comply covers ISO 9001, 45001 and 14001. For ISO 27001, we provide consulting and ongoing maintenance support.
Which version of ISO 27001 should we certify to?
ISO/IEC 27001:2022, the current version. New certifications are issued against the 2022 version.
Clarify the scope before you start.
Book a free 30-minute call to discuss your information security requirement, the information in scope and the work involved.
