Service

GIC là tổ chức đánh giá sự phù hợp, hoạt động trong lĩnh vực Thử nghiệm - Giám định - Chứng nhận

System Certification

ISO/IEC 27001:2022 Information Security Management System Certification

I. INTRODUCTION TO ISO/IEC 27001:2022 CERTIFICATION SERVICES
ISO/IEC 27001 Certification

ISO/IEC 27001:2022 is the international standard specifying requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). Jointly published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), the standard enables organizations to manage information security risks systematically and in a manner appropriate to their context, size, objectives and needs.

An ISMS is designed to protect the confidentiality, integrity and availability of information; it may also address other properties such as authenticity, accountability, non-repudiation and reliability where appropriate. Its protection scope is not limited to IT systems or cybersecurity, but encompasses information in all forms, people, processes, technology, physical facilities and relevant third parties.

ISO/IEC 27001:2022 is applicable to organizations of every type and size. It requires an organization to define the scope of its ISMS; identify interested parties and applicable legal, regulatory and contractual requirements; assess risks based on their sources, consequences and likelihood; select risk treatment options; monitor system effectiveness; and continually improve on the basis of evidence.

Key elements of ISO/IEC 27001:2022 include:

  • ISMS context, scope and governance: Define the boundaries, interfaces, dependencies, locations, processes, systems, services and third parties within the management scope; establish policies, roles, responsibilities and leadership commitment.
  • Information security risk assessment: Apply consistent criteria to identify, analyze and evaluate risks relating to information assets, threats, vulnerabilities, consequences and likelihood.
  • Risk treatment and Statement of Applicability: Select treatment options, determine necessary controls, establish an information security risk treatment plan and a Statement of Applicability (SoA), and justify the inclusion or exclusion of reference controls.
  • Information security controls: Annex A provides 93 reference controls organized into four themes: organizational, people, physical and technological. Controls must be selected on the basis of risk and applicable requirements, and an organization may implement additional controls where necessary.
  • Operation, monitoring and response: Manage change, suppliers, cloud services, access, configuration, backup, logging, vulnerabilities, information security incidents and the ability to maintain information security during disruption.
  • Performance evaluation and improvement: Establish indicators, monitor and measure performance, conduct internal audits and management reviews, address nonconformities, implement corrective actions and continually improve the ISMS.

ISO/IEC 27001:2022/Amd 1:2024 adds climate change considerations to the review of organizational context and interested-party requirements. An organization must determine whether climate change is a relevant issue and, where appropriate, consider its effects on power supply, cooling, data centers, technology supply chains, remote working arrangements, resilience, and emerging customer or regulatory requirements.

Benefits of implementing and obtaining ISO/IEC 27001:2022 certification
  • Systematic risk management: Helps prioritize resources according to risk levels instead of relying on fragmented technical solutions or reacting only after incidents occur.
  • Information protection and enhanced resilience: Strengthens the confidentiality, integrity and availability of data and supports the continuity of critical activities during disruption.
  • Compliance support: Provides a structured mechanism for managing legal and regulatory requirements, industry obligations, personal data protection, intellectual property and contractual confidentiality commitments.
  • Stronger third-party control: Manages risks arising from suppliers, cloud services, outsourced activities, and information processing and sharing chains.
  • Greater trust and competitive advantage: Provides independent evidence for supplier due diligence, tenders, customer requirements and participation in international supply chains.
  • Support for integrated management systems: Provides a foundation for integration with ISO 9001, ISO 22301, ISO/IEC 20000-1, ISO/IEC 27701 and other risk management, privacy or cybersecurity frameworks.

GIC Vietnam provides independent ISO/IEC 27001:2022 Information Security Management System certification services for organizations seeking to demonstrate that their ISMS conforms to the international standard. Certification is voluntary, does not replace compliance obligations and does not guarantee that all security incidents or data breaches will be prevented. It is also not certification of an individual product, platform or technical solution outside the defined ISMS scope.

This service is suitable for:
  • Organizations establishing a new Information Security Management System or standardizing an existing system in accordance with ISO/IEC 27001:2022.
  • Organizations that manage sensitive information, personal data, intellectual property, financial information or information entrusted to them by customers and business partners.
  • Software, SaaS, cloud service, data center, fintech, e-commerce, healthcare, telecommunications or business process outsourcing providers.
  • Organizations requiring certification to satisfy legal, contractual, customer, tender, supplier-assessment or supply-chain requirements.
  • Organizations operating across multiple locations, supporting remote workforces, relying on suppliers or seeking to integrate their ISMS with other management systems.
II. CERTIFICATION PROCESS
Step 1
Certification application & application review

1. Certification application & application review

The organization contacts GIC Vietnam for guidance and provides the information necessary for certification, including the proposed ISMS scope, locations, organizational structure, number of relevant personnel, activities and types of information, key systems and technologies, data centers or cloud services, outsourced processes, and applicable legal and contractual requirements. GIC Vietnam reviews the application to determine its competence, audit duration, scope and audit conditions, and then agrees with the organization on certification fees and the certification contract.

Step 2
Audit planning & preparation

2. Audit planning & preparation

GIC Vietnam establishes the certification program, appoints an audit team with competence appropriate to the organization's sector, technologies and ISMS complexity, and prepares a detailed audit plan. The plan defines the audit objectives, scope, criteria, locations, schedule, audit methods and activities to be sampled. Information, records and evidence supplied by the organization are managed in accordance with the confidentiality requirements applicable to certification activities.

Step 3
Audit process

3. Audit process

The audit is conducted in two stages:

  • Stage 1: Review the ISMS context, scope and documented information; risk assessment and treatment methodology; Statement of Applicability; objectives; internal audit; and management review, and confirm readiness for Stage 2.
  • Stage 2: Evaluate the implementation, conformity and effectiveness of the ISMS at locations within the certification scope. Principal activities include: Opening meeting → Interviews → Review of records → Sampling of processes, systems and controls → Consolidation of findings → Closing meeting. A certification audit does not replace penetration testing or a comprehensive technical security assessment.
Step 4
Audit report & handling of nonconformities

4. Audit report & handling of nonconformities

The audit team prepares a report setting out its conclusions and any identified nonconformities. Where necessary, the organization takes immediate correction, analyzes the root cause, and proposes and implements corrective action within the prescribed timeframe. GIC Vietnam reviews the evidence and may conduct a follow-up audit where necessary before submitting the file for independent review.

Step 5
Review & certification

5. Review & certification

A person independent of the audit team reviews the complete certification file, audit report and evidence of corrective action and makes the certification decision. When all requirements have been met, GIC Vietnam decides to issue an ISO/IEC 27001:2022 certificate with a clearly defined scope. The certificate remains valid throughout a three-year certification cycle, provided that the organization continues to conform and completes the required surveillance audits.

Step 6
Periodic surveillance & recertification

6. Periodic surveillance & recertification

During the certification cycle, GIC Vietnam conducts periodic surveillance audits to confirm that the ISMS continues to be maintained and remains effective. The first surveillance audit is conducted no later than 12 months after the initial certification decision. The organization must notify GIC Vietnam of significant changes to its scope, locations, technology or ownership, or of serious incidents that may affect certification. Before the certificate expires, a recertification audit is conducted to determine whether certification may be renewed for the next cycle.

III. WHY CHOOSE GIC VIETNAM?
International reputation and broad recognition

GIC is a reputable certification body whose certification marks are widely recognized through accreditations from leading organizations such as UKAS (United Kingdom), JASANZ (Australia – New Zealand), CPSC (United States), SAC (Singapore), CNAS (China) and VICAS (Vietnam). Certificates issued by GIC are recognized globally through the mutual recognition arrangements (MRAs) of the International Accreditation Forum (IAF) and the Asia Pacific Accreditation Cooperation (APAC). This helps organizations reduce technical barriers and facilitates access to international markets.

Professional, impartial and cost-effective service

GIC Vietnam provides services in accordance with the rigorous standards applied in Europe and North America, ensuring independence, impartiality and professionalism throughout the certification audit process. In addition to high service quality, GIC offers reasonable and competitive fees, enabling organizations to use their investment resources efficiently while obtaining recognition in accordance with international benchmarks.

CONTACT INFORMATION:
GIC VIETNAM
🏢 Hanoi: 12F, 14 Lang Ha Building, Giang Vo Ward
☎️ Tel: 024.6275 2268 | 📱Hotline: 0984609469
📧 Email: tuandm@gicvn.vn
🏢 Ho Chi Minh City: R502, 160 Nam Ky Khoi Nghia,
☎️ Tel: 028.3930 7936
Chia sẻ:

System Certification

Verification, Validation

  • ESG Reports

    The ESG (Environmental, Social, and Governance) framework helps businesses measure their sustainability impacts, guide long-term risk management strategies, and create positive value for both the community and stakeholders.
  • GHG Inventory Reports

    Building trust - Stepping steadily into integration. Independent verification of greenhouse gas inventory reports enhances the reliability and transparency of emissions data and meets international standards.
  • Product Carbon Footprint (CFP)

    Product Carbon Footprint Verification – A solution to build trust and elevate product value in the global supply chain.
  • CBAM Embedded Emissions

    CBAM embedded emissions verification independently assesses monitoring approaches, activity data, emissions calculations and supporting evidence at installations producing CBAM goods. The process helps businesses improve data reliability, identify misstatements and prepare to meet EU CBAM reporting and verification requirements.
  • Singapore Green Labelling

    Green Label helps identify environmentally friendly products and enhances the company's image.

Product, process certification

  • Product Certification

    Product certification is the process of assessing and confirming that a product meets the technical, quality and safety requirements of the applicable standard. Achieving certification helps demonstrate product reliability, build consumer confidence and strengthen the brand’s competitiveness in the market.
  • Technical Regulation Conformity Certification

    Technical regulation compliance certification is the process of evaluating and verifying that products conform to national technical regulations. Understanding the relevant regulations and certification procedures helps businesses ensure strict legal compliance, guarantee product safety, and successfully introduce their goods into the...
  • Traceability

    Certification of the Traceability System according to the ISO 22005 helps businesses in the food and feed chain ensure transparency in the movement of goods, strictly control food safety risks, and simultaneously meet the stringent requirements of partners, consumers, and international...
  • ISO 3834 Welding Process

    ISO 3834 certification service evaluates a manufacturer’s capability to control metallic-material fusion welding against ISO 3834-2, ISO 3834-3 or ISO 3834-4. The assessment covers personnel, WPS and WPQR/PQR, materials, equipment, inspection, NDT and welding quality records.
  • CE Marking

    Affixing the CE mark is a mandatory requirement for many product groups when placed on the EEA market. This article helps Vietnamese businesses determine the scope of application, manufacturer responsibilities, cases requiring a Notified Body, technical documentation, and the conformity assessment...

Improvement Tools Certification

  • 5S Certification

    5S builds a professional image and fosters a dynamic, creative, and efficient work environment.
  • Lean Manufacturing

    Lean optimizes the production process by eliminating waste and increasing customer value.
  • KPIs

    KPI is a metric to evaluate goal achievement for a business, team, or individual.

Coaching and Training