ISO 27001 Lead Auditor · Domain 6
Certification Lifecycle and Accreditation
About 12% of the exam
The three year cycle
- Application
- Stage 1
- Stage 2
- Certification decision
- Surveillance one
- Surveillance two
- Recertification
- Certificate validity
- three years from the decision
- First surveillance
- within twelve months of stage 2
- Surveillance frequency
- at least once each year
- Cycle coverage
- the whole ISMS across three years
- Recertification
- completed before the certificate expires
- Stage 1 again
- only after significant change
Surveillance samples the system; recertification looks at all of it again
Who is who in the scheme
- Accreditation body
- assesses the certification bodies
- Certification body
- audits and issues the certificate
- Accreditation forum
- arrangement for mutual recognition
- ISO/IEC 17021-1
- requirements for management system bodies
- ISO/IEC 27006
- extra rules for ISMS certification
- Decision maker
- independent of the audit team
- Impartiality committee
- shields the body from pressure
Accreditation is what makes one certificate mean the same thing as another; without it the market cannot compare them
Certificate scope
- Names activities, services and locations
- Describes only what was assessed
- Cannot include planned future services
- Closed sites must be removed
- Misleading scope harms the whole scheme
- Reviewed at every surveillance visit
Audit time and personnel
- Based on effective number of personnel
- Counts people performing in scope work
- Part time counted proportionally
- Complexity, sites and technology adjust it
- Reductions bounded by scheme rules
- Documented justification kept on file
Suspension and withdrawal
- Major finding left unresolved
- Refusing a surveillance visit
- Misuse of the certification mark
- Suspension is temporary and time bound
- Withdrawal ends the certification entirely
- Appeals handled by uninvolved people
What surveillance must cover
- Internal audit and management review always
- Status of previous corrective actions
- Complaints and use of the mark
- Changes to scope, sites or technology
- Sampled controls and ISMS processes
- Progress against continual improvement
- Effective operation since the last visit
Certification depends on continued conformity, so a surveillance finding can absolutely put the certificate at risk
Transfer between bodies
- Certificate must be valid and accredited
- Review the certificate and recent reports
- Open nonconformities resolved before transfer
- Scope carried across unchanged
- New body may audit before accepting
Mark and claim rules
- Claims limited to the certified scope
- Never imply that products are certified
- Mark used per the body rules
- Misuse can trigger suspension
- Status verifiable by any customer
Special situations
- Key staff left
- test whether processes still operate
- Accreditation withdrawn
- certificates lose their accredited status
- Merger mid cycle
- scope and risk reassessed
- Serious incident
- may trigger a special audit
- Paper only ISMS
- cannot be certified at all
Preparing an organization
- Run a full internal audit first
- Hold a genuine management review
- Close known gaps before stage 1
- Build operating evidence over months
- Brief staff on the policy
- Keep the SoA current
Rapid recall: cycle numbers
- Certificate validity
- three years
- Surveillance
- at least annually
- First surveillance
- within twelve months of stage 2
- Recertification
- before the expiry date
- Stage gap
- long enough to close gaps
- Whole ISMS
- covered across the cycle
Impartiality safeguards
- No consulting for the client audited
- Auditor rotation across the cycle
- Decision made by an uninvolved reviewer
- Financial pressure declared and managed
- Impartiality risks reviewed regularly
Reference strip: cycle, bodies, scope, sanctions, proof
Cycle
- Stage 1, stage 2, decision
- Annual surveillance, three year certificate
- Recertification before expiry
Bodies
- Accreditation body oversees
- Certification body audits
- Independent reviewer decides
Scope
- Only what was assessed
- No future or planned services
- Checked at each surveillance
Sanctions
- Suspension is time bound
- Withdrawal ends certification
- Appeals decided by others
Proof
- Internal audit and review records
- Corrective action closure evidence
- Operating records across the cycle
Quick exam traps
- Trap: A certificate lasts indefinitely once issued
- Trap: Surveillance findings cannot affect an existing certificate
- Trap: The audit team that found the evidence also grants the certificate
- Trap: A scope may name a service the organization plans to launch
- Trap: An unaccredited certificate carries the same weight in the market
- Trap: Recertification is just a slightly longer surveillance visit
cybercertprep.com · original revision sheet written from the public body of knowledge