ISO 27001 Certification Support
ISO 27001 is the international "gold standard" for information security. If your organisation has outgrown Cyber Essentials and Cyber Assurance, or a customer or contract now asks for ISO 27001 specifically, Regola can help you prepare for it and work with our partners to take you through to certification.
What is ISO 27001?
ISO 27001, in its current 2022 version, is the international standard for an Information Security Management System (ISMS). It sets out a risk-based framework for protecting the confidentiality, integrity and availability of your information, supported by a set of security controls in Annex A. Certification is awarded by an accredited international certification body.
How ISO 27001 relates to Cyber Assurance
Cyber Essentials
Core Technical Controls
Cyber Assurance
Governance & Resilience
ISO 27001
International Standard
For most small and medium organisations, IASME Cyber Assurance is the natural starting point, and ISO 27001 is the step beyond it. If you already hold Cyber Assurance Level 2, you have done much of the groundwork, and ISO 27001 is only a small hill to climb from there. The key difference is who awards it.
Cyber Assurance is UK-developed and certified through IASME. ISO 27001 sits outside IASME, and the body awarding certification is an international standards organisation rather than a UK Government scheme. That international recognition is often exactly why organisations pursue it.
How Regola Helps
We are honest about our role here. Regola is an IASME certification body, so we certify Cyber Essentials and Cyber Assurance directly. For ISO 27001, we help you get audit-ready and our trusted partners carry out the certification itself.
That means we can:
Assess where you are against the ISO 27001 requirements and identify the gaps.
Prepare your documentation, processes and people for an audit by an international standards certification body.
Build on the governance, policies and controls you already have from Cyber Essentials and Cyber Assurance.
Introduce and work alongside our partners who take you through to certification.
Where We Work
We're based in Torquay and operate across the UK, with many clients both in and outside Devon, including:
North Devon
Exeter
Taunton
Barnstaple
Cullompton
Mid Devon
Plymouth
Honiton
Torquay
Crediton
South Devon
Newton Abbot
Where to start
If you are not yet certified to Cyber Essentials or Cyber Assurance, that is usually the most cost-effective place to begin, and it lays a solid foundation for ISO 27001 later. If you already know ISO 27001 is your target, we can plan the whole route with you from the outset.
Not sure whether ISO 27001 is the right target for you, or whether Cyber Assurance would do the job? Give us a shout and we will talk it through honestly.
