ISO/IEC 27001:2022 Information Security Management System Certification
ISO/IEC 27001:2022 is the international standard specifying requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). Jointly published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), the standard enables organizations to manage information security risks systematically and in a manner appropriate to their context, size, objectives and needs.
An ISMS is designed to protect the confidentiality, integrity and availability of information; it may also address other properties such as authenticity, accountability, non-repudiation and reliability where appropriate. Its protection scope is not limited to IT systems or cybersecurity, but encompasses information in all forms, people, processes, technology, physical facilities and relevant third parties.
ISO/IEC 27001:2022 is applicable to organizations of every type and size. It requires an organization to define the scope of its ISMS; identify interested parties and applicable legal, regulatory and contractual requirements; assess risks based on their sources, consequences and likelihood; select risk treatment options; monitor system effectiveness; and continually improve on the basis of evidence.
Key elements of ISO/IEC 27001:2022 include:
- ISMS context, scope and governance: Define the boundaries, interfaces, dependencies, locations, processes, systems, services and third parties within the management scope; establish policies, roles, responsibilities and leadership commitment.
- Information security risk assessment: Apply consistent criteria to identify, analyze and evaluate risks relating to information assets, threats, vulnerabilities, consequences and likelihood.
- Risk treatment and Statement of Applicability: Select treatment options, determine necessary controls, establish an information security risk treatment plan and a Statement of Applicability (SoA), and justify the inclusion or exclusion of reference controls.
- Information security controls: Annex A provides 93 reference controls organized into four themes: organizational, people, physical and technological. Controls must be selected on the basis of risk and applicable requirements, and an organization may implement additional controls where necessary.
- Operation, monitoring and response: Manage change, suppliers, cloud services, access, configuration, backup, logging, vulnerabilities, information security incidents and the ability to maintain information security during disruption.
- Performance evaluation and improvement: Establish indicators, monitor and measure performance, conduct internal audits and management reviews, address nonconformities, implement corrective actions and continually improve the ISMS.
ISO/IEC 27001:2022/Amd 1:2024 adds climate change considerations to the review of organizational context and interested-party requirements. An organization must determine whether climate change is a relevant issue and, where appropriate, consider its effects on power supply, cooling, data centers, technology supply chains, remote working arrangements, resilience, and emerging customer or regulatory requirements.
Benefits of implementing and obtaining ISO/IEC 27001:2022 certification
- Systematic risk management: Helps prioritize resources according to risk levels instead of relying on fragmented technical solutions or reacting only after incidents occur.
- Information protection and enhanced resilience: Strengthens the confidentiality, integrity and availability of data and supports the continuity of critical activities during disruption.
- Compliance support: Provides a structured mechanism for managing legal and regulatory requirements, industry obligations, personal data protection, intellectual property and contractual confidentiality commitments.
- Stronger third-party control: Manages risks arising from suppliers, cloud services, outsourced activities, and information processing and sharing chains.
- Greater trust and competitive advantage: Provides independent evidence for supplier due diligence, tenders, customer requirements and participation in international supply chains.
- Support for integrated management systems: Provides a foundation for integration with ISO 9001, ISO 22301, ISO/IEC 20000-1, ISO/IEC 27701 and other risk management, privacy or cybersecurity frameworks.
GIC Vietnam provides independent ISO/IEC 27001:2022 Information Security Management System certification services for organizations seeking to demonstrate that their ISMS conforms to the international standard. Certification is voluntary, does not replace compliance obligations and does not guarantee that all security incidents or data breaches will be prevented. It is also not certification of an individual product, platform or technical solution outside the defined ISMS scope.
This service is suitable for:
- Organizations establishing a new Information Security Management System or standardizing an existing system in accordance with ISO/IEC 27001:2022.
- Organizations that manage sensitive information, personal data, intellectual property, financial information or information entrusted to them by customers and business partners.
- Software, SaaS, cloud service, data center, fintech, e-commerce, healthcare, telecommunications or business process outsourcing providers.
- Organizations requiring certification to satisfy legal, contractual, customer, tender, supplier-assessment or supply-chain requirements.
- Organizations operating across multiple locations, supporting remote workforces, relying on suppliers or seeking to integrate their ISMS with other management systems.
1. Certification application & application review
The organization contacts GIC Vietnam for guidance and provides the information necessary for certification, including the proposed ISMS scope, locations, organizational structure, number of relevant personnel, activities and types of information, key systems and technologies, data centers or cloud services, outsourced processes, and applicable legal and contractual requirements. GIC Vietnam reviews the application to determine its competence, audit duration, scope and audit conditions, and then agrees with the organization on certification fees and the certification contract.
2. Audit planning & preparation
GIC Vietnam establishes the certification program, appoints an audit team with competence appropriate to the organization's sector, technologies and ISMS complexity, and prepares a detailed audit plan. The plan defines the audit objectives, scope, criteria, locations, schedule, audit methods and activities to be sampled. Information, records and evidence supplied by the organization are managed in accordance with the confidentiality requirements applicable to certification activities.
3. Audit process
The audit is conducted in two stages:
- Stage 1: Review the ISMS context, scope and documented information; risk assessment and treatment methodology; Statement of Applicability; objectives; internal audit; and management review, and confirm readiness for Stage 2.
- Stage 2: Evaluate the implementation, conformity and effectiveness of the ISMS at locations within the certification scope. Principal activities include: Opening meeting → Interviews → Review of records → Sampling of processes, systems and controls → Consolidation of findings → Closing meeting. A certification audit does not replace penetration testing or a comprehensive technical security assessment.
4. Audit report & handling of nonconformities
The audit team prepares a report setting out its conclusions and any identified nonconformities. Where necessary, the organization takes immediate correction, analyzes the root cause, and proposes and implements corrective action within the prescribed timeframe. GIC Vietnam reviews the evidence and may conduct a follow-up audit where necessary before submitting the file for independent review.
5. Review & certification
A person independent of the audit team reviews the complete certification file, audit report and evidence of corrective action and makes the certification decision. When all requirements have been met, GIC Vietnam decides to issue an ISO/IEC 27001:2022 certificate with a clearly defined scope. The certificate remains valid throughout a three-year certification cycle, provided that the organization continues to conform and completes the required surveillance audits.
6. Periodic surveillance & recertification
During the certification cycle, GIC Vietnam conducts periodic surveillance audits to confirm that the ISMS continues to be maintained and remains effective. The first surveillance audit is conducted no later than 12 months after the initial certification decision. The organization must notify GIC Vietnam of significant changes to its scope, locations, technology or ownership, or of serious incidents that may affect certification. Before the certificate expires, a recertification audit is conducted to determine whether certification may be renewed for the next cycle.
International reputation and broad recognition
GIC is a reputable certification body whose certification marks are widely recognized through accreditations from leading organizations such as UKAS (United Kingdom), JASANZ (Australia – New Zealand), CPSC (United States), SAC (Singapore), CNAS (China) and VICAS (Vietnam). Certificates issued by GIC are recognized globally through the mutual recognition arrangements (MRAs) of the International Accreditation Forum (IAF) and the Asia Pacific Accreditation Cooperation (APAC). This helps organizations reduce technical barriers and facilitates access to international markets.
Professional, impartial and cost-effective service
GIC Vietnam provides services in accordance with the rigorous standards applied in Europe and North America, ensuring independence, impartiality and professionalism throughout the certification audit process. In addition to high service quality, GIC offers reasonable and competitive fees, enabling organizations to use their investment resources efficiently while obtaining recognition in accordance with international benchmarks.
GIC VIETNAM
🏢 Hanoi: 12F, 14 Lang Ha Building, Giang Vo Ward
☎️ Tel: 024.6275 2268 | 📱Hotline: 0984609469
📧 Email: tuandm@gicvn.vn
🏢 Ho Chi Minh City: R502, 160 Nam Ky Khoi Nghia,
☎️ Tel: 028.3930 7936