Guide

How to maintain ISO 27001 certification

Certification proves the system met the standard on the day it was assessed. Keeping it means running the management system continuously — here is what that involves through a three-year cycle.

The most common reason organisations struggle at surveillance audits is not a technical failure. It is that the ISMS stopped operating shortly after the certificate arrived, and everything had to be reconstructed a fortnight before the auditor returned. The standard is explicit that the system must be maintained and continually improved, and auditors look for evidence spread across the year rather than a burst of activity.

The certification cycle

Certification is normally granted for three years. Surveillance audits take place during that period, usually annually, sampling parts of the system. At the end of the cycle a recertification audit reassesses the ISMS as a whole. Each visit will look at what changed, what went wrong, what you found yourself and what you did about it.

A workable annual rhythm

Rather than a single pre-audit push, spread the mandatory and useful activity across the year:

  • Monthly or quarterly: review open actions and nonconformities, log incidents, check that starters and leavers were processed correctly, review changes to systems and suppliers.
  • Quarterly or half-yearly: review the risk register with risk owners, confirm treatment progress, review supplier risk, sample control effectiveness.
  • Annually: review and re-approve policies where required, complete the internal audit programme, hold management review, set and assess security objectives, test business continuity arrangements where in scope.

Keep the risk register alive

A risk register that has not changed in twelve months tells an auditor that nobody is looking at it. Risks should move as the business does: new customers, new systems, new suppliers, new locations, changes in staffing. Record when a risk was reviewed, by whom and what changed.

Policies and version control

Policies must reflect current practice. When a process changes, the document should change with it, be re-approved at the right level and be communicated. Version history, approval dates and evidence of communication are all routinely sampled.

Evidence is the currency of an audit

Almost every finding comes down to evidence: it either exists, is current and can be found, or it cannot. Decide where records live and keep them there as work happens — access reviews, training records, supplier reviews, incident logs, change approvals, backup and restore tests, meeting minutes.

Internal audit and management review

Both are mandatory and both are frequently rushed. Internal audit should be planned to cover the whole system over a defined programme, carried out by someone objective, and produce findings that are actually acted upon. Management review should consider the defined inputs — performance, feedback, risk status, nonconformities, objectives, improvement opportunities — and record decisions and resource allocation.

Corrective action, done properly

When something goes wrong, the standard expects you to react, evaluate the need to eliminate the cause, act, review effectiveness and update the risk assessment if necessary. A corrective action closed with “staff reminded” will often be reopened at the next audit. Address the cause, then evidence that the fix held.

Change is what auditors probe

Acquisitions, new premises, a new cloud platform, a change of managed service provider, significant headcount change or a new product line all affect the ISMS. Each should be visible somewhere: risk assessment updated, scope reconsidered, supplier assessed, policies adjusted.

Who owns it?

Maintenance fails when ownership is unclear. Someone has to be responsible for keeping the programme moving, chasing evidence, running reviews and reporting to management. Where there is no internal candidate with the time or experience, ongoing CISO support fills that role without the cost of a permanent appointment.

Before a surveillance audit

See our guide to preparing for an ISO 27001 surveillance audit for a focused readiness checklist covering what auditors typically request and how to brief the people they will interview.

Has your ISMS drifted?

If policies are out of date, actions are open or nobody owns the system, we can review where it stands and bring it back to a maintainable state.

Or email info@isosecurity.co.uk