var Cli_Data = {"nn_cookie_ids":[],"cookielist":[],"non_necessary_cookies":[],"ccpaEnabled":"","ccpaRegionBased":"","ccpaBarEnabled":"","strictlyEnabled":["necessary","obligatoire"],"ccpaType":"gdpr","js_blocking":"1","custom_integration":"","triggerDomRefresh":"","secure_cookies":""};
var cli_cookiebar_settings = {"animate_speed_hide":"500","animate_speed_show":"500","background":"#f5f5f5","border":"#b1a6a6c2","border_on":"","button_1_button_colour":"#ec8c08","button_1_button_hover":"#bd7006","button_1_link_colour":"#ffffff","button_1_as_button":"1","button_1_new_win":"","button_2_button_colour":"#333","button_2_button_hover":"#292929","button_2_link_colour":"#717c7d","button_2_as_button":"","button_2_hidebar":"","button_3_button_colour":"#ec8c08","button_3_button_hover":"#bd7006","button_3_link_colour":"#ffffff","button_3_as_button":"1","button_3_new_win":"","button_4_button_colour":"#ec8c08","button_4_button_hover":"#bd7006","button_4_link_colour":"#ffffff","button_4_as_button":"1","button_7_button_colour":"#61a229","button_7_button_hover":"#4e8221","button_7_link_colour":"#fff","button_7_as_button":"1","button_7_new_win":"","font_family":"inherit","header_fix":"","notify_animate_hide":"1","notify_animate_show":"","notify_div_id":"#cookie-law-info-bar","notify_position_horizontal":"right","notify_position_vertical":"bottom","scroll_close":"","scroll_close_reload":"","accept_close_reload":"","reject_close_reload":"","showagain_tab":"1","showagain_background":"#fff","showagain_border":"#000","showagain_div_id":"#cookie-law-info-again","showagain_x_position":"100px","text":"#717c7d","show_once_yn":"","show_once":"10000","logging_on":"","as_popup":"","popup_overlay":"1","bar_heading_text":"","cookie_bar_as":"banner","popup_showagain_position":"bottom-right","widget_position":"left"};
var log_object = {"ajax_url":"https://www.episodeltd.com/wp-admin/admin-ajax.php"};
//# sourceURL=cookie-law-info-js-extra
ISO 27001 : 2013, Information security management systems requirements, is a definitive global model for best practice in managing information safely and securely.
How do I get ISO 27001?
Don’t be put off by thinking ISO 27001 information security management systems requirements is too complex a thing to do. We aren’t saying it’s simple, but with us doing the bulk of the work for you, including managing the whole process, it is relatively straightforward.
There are essentially 6 stages to becoming and staying certified to ISO 27001:
Establish a system that complies with the standard
Identify which of the 114 control objectives, in 13 categories, apply to your business, why, and what you are doing to control them
Make everyone aware of the system and any changes in ways of working that have come about
Operate the system to
a. Make sure it works efficiently
b. Build evidence of compliance with the requirements of the standard
c. Get staff familiar with it
Appoint a “certification body” to independently assess whether you comply with the standard. We recommend you choose a UKAS accredited body (see below)
Keep using the system once it has been certified (to keep the certificate)
There is more detailed information below about the various stages you need to go through.
Your ISO 27001 certification journey
Getting Started
Provide a comprehensive briefing of what the standard asks you to do in simple to understand terms
Begin to understand in detail how you operate
Set a timetable and stick to it
Decide what you want covered by the certificate – which sites, products and services.
Put the right resources in place
Collect all existing documentation
Establish a dedicated client portal on our collaboration and document sharing platform
Begin to identify which of the 114 control mechanisms apply and how to address them
Begin identifying and recording all your information assets
Begin creating an Information security asset register
Begin understanding what legislation applies & what you do to comply
Implementing
Establish a detailed project plan in our online project management platform (and stick to it)
Undertake a technical audit of your system (with our cyber security/info sec partner)
Carry out a Data Protection Impact Assessment (good practice and mandatory for GDPR)
Decide with you what you need operationally
Map out your business processes
Complete a gap analysis between what the standard requires and what you have/do already
Implement the system
Complete required documentation (Statement of Applicability, Asset register, etc.)
Submit the system to Episode Head Office for final QC checks
We return it you for your final approval
Separate consultant Internally audit the system
Carry out a management review
Certification
Work with you to select and appoint a UKAS accredited certification body.
Be onsite throughout the certification process
Address any issues that arise during the audit
Brief you on post-certification activity
a. 3 year cycle of annual surveillance audits and
b. what you need to do throughout the year to maintain the system
Agree where the finished, certified system should be housed
ISO 27001:2013, Information security management systems requirements, provides a framework for an Information Security Management System [ISMS], helping you to maintain and improve your information security needs. It also aids compliance with data protection legislation and provide assurance to your stakeholders. It provides a best practice
An ISMS is a systematic approach to managing sensitive company information so that it remains secure. It includes people, processes and IT systems by applying a risk management process.
It can help small, medium and large businesses in any sector keep information assets secure.
Beyond the ancillary system administration requirements (policy, objectives, document control procedure, internal audit procedure, etc.), the key aspects of an ISMS are
reviewing the organisation’s status with regards to Annex A – Control Objectives and Controls (a list of 114 entries)
produce a Statement of Applicability that contains the necessary controls and justification for inclusions, whether they are implemented or not, and the justification for exclusions of controls from Annex A.
produce an asset register (including people and buildings, as well as the more obvious IT infrastructure)
Simply put, you must review the 114 points, grouped under 13 headings. We must decide if they apply (if not, why not), how you intend to comply with that requirement and a plan to constantly improve performance against them.
When done correctly, gaining and maintaining ISO 27001 certification is not as complicated as most think. Trust Episode to make ISO work for you, not the other way around.
Contact us today on 0113 8019001 orclick here to email us
It was only by utilising the expert guidance and experience of Episode that Thurston Group was able to attain certification within an exceptionally challenging time frame. We therefore offer our thanks to Episode Ltd. For the diligent and professional services provided. We also look forward to working with them again soon and would not hesitate to recommend their services."
Peter Spieight, Senior Divisional Director, Thurston Group, Wakefield
Roger's support was invaluable in terms of gap analysis, recommendations for improvement, and facilitation of the certification process. I would strongly recommend Roger to any organisation wishing to develop or improve its management systems, in a way which minimizes bureaucracy, and focuses on best serving the needs of the organization.
Gary Evans, Flour Corporation, Abu Dhabi
Roger and Sandy at Episode were great in helping us achieve not only one but two ISO standards 9001:2015 and 14001:2015. Episode were extremely helpful from the onset, they were able to break down the ISO standard so they were easily comprehensible and well applied to our business in a sustainable manner. They are a company that offers a guaranteed certification at the end of the process and they delivered it. I believe that the work completed during this process was key to us having won the Leeds Bid contract.
If Sandy hasn’t already updated you we are delighted to say we passed the transition audit for ISO 9001 and ISO 14001. Sandy did an absolutely fab job and all credit to her, we have loved having both of you here it’s been a pleasure.
I have had a brief chat with Morgan[the CEO] about the next steps and how we manage things going forwards. Morgan will be in touch with you soon about this and getting Episode/Sandy back in on a regular basis. Once again many thanks for everything and especially to Sandy!!
Morag Tearne, HR and Health & Safety Manager, H. Slingsby plc, Shipley
Episode is always prepared to go the extra mile. When in a tight spot the lead consultant carried out an audit for us at very short notice (on a Sunday afternoon) to keep us on track. What is important to us is the advice they give us is practical and tailored to us. The quality of output Episode produces is very high.
This has resulted in us having a multi-year managed service from Episode so as a company we know our ISO 9001, ISO 14001 and ISO 45001 integrated system is up to date and working for us.
Gareth Walters, Financial Controller, Sports Turf Research Institute, Bingley.
When asked by Episode what three things they do well, and what three things they could improve upon, my answers were:
Done well
1. Client Communication, responded to queries very quickly
2. Requirements of the standard were communicated in a simple manner.
3. Assistance from initial implementation to date of assessment was very good.
I can honestly there is nothing I feel they should improve upon.
Paul Hunneybell, Operations Manager, Fenland Fire Contracts Limited, Luton
The consultant worked with the team in Scott Bader Middle East Ltd. to completely re-engineer our Integrated Management System incorporating ISO 9001, ISO 14001 and OHSAS 18001. Until then we were slaves to the ISO audits, with the systems not adding much value beyond certification. Now we have a business management system that really works for us and is truly integrated into our operations. We were also successfully re-certified along the way.
John Kemp, CEO Scott Bader Middle East, Africa and Asia
The consultant really focused on making our systems and processes work better for us, not just help us comply with ISO 9001. He was able to work with Department Heads and Senior Management to shape their strategic thinking about quality and business objectives without telling them what they had to do because the standard says so.
Karim D'Alessandro, HSE Director, Shelf Drilling Inc.
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
Cookie
Duration
Description
cookielawinfo-checkbox-analytics
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional
11 months
The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy
11 months
The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.