DCG Logo DCG Logo
  • About Us

    Where there's unique perspective, there's DGC. 
    Learn more

    • Service Philosophy
    • Team
    • News & Events
    • Community Involvement
  • Services
    • Private Client
    • Business Tax
    Assurance & Accounting
    • Accounting & Business Advisory Services
    • Audit, Review & Compilation
    • Employee Benefit Plan Audit
    • Overhead Rate Audit
    Business Advisory
    • Alternative Dispute Resolution
    • Bankruptcy & Restructuring
    • Forensic Accounting
    • Human Capital Consulting
    • IT Risk Assurance & Advisory
    • Litigation Support
    • Succession Planning
    • Technical Accounting Advisory
    • Transaction Advisory
    • Valuation
  • Industries

    Architecture & Engineering

    Healthcare

    Manufacturing & Distribution

    Not-for-Profit

    Professional Services

    Restaurant & Hospitality

    Real Estate

    Retail & Consumer

    Technology

  • Perspectives

    Articles & Podcasts

    Case Studies

    Newsletters

  • Careers

    DGC is looking for talented professionals to join our team.
    Learn more 

    Working Environment

    Life @ DGC

    Benefits

    Professional Development

    Student Resources

    View Open Positions

  • Contact Us

    Send a Message

    Office Locations & Directions

  • Client Portal
  • LinkedIn
  • Twitter
  • Facebook
  • About Us

    Where there's unique perspective, there's DGC. 
    Learn more

    • Service Philosophy
    • Team
    • News & Events
    • Community Involvement
  • Services
    • Private Client
    • Business Tax
    Assurance & Accounting
    • Accounting & Business Advisory Services
    • Audit, Review & Compilation
    • Employee Benefit Plan Audit
    • Overhead Rate Audit
    Business Advisory
    • Alternative Dispute Resolution
    • Bankruptcy & Restructuring
    • Forensic Accounting
    • Human Capital Consulting
    • IT Risk Assurance & Advisory
    • Litigation Support
    • Succession Planning
    • Technical Accounting Advisory
    • Transaction Advisory
    • Valuation
  • Industries

    Architecture & Engineering

    Healthcare

    Manufacturing & Distribution

    Not-for-Profit

    Professional Services

    Restaurant & Hospitality

    Real Estate

    Retail & Consumer

    Technology

  • Perspectives

    Articles & Podcasts

    Case Studies

    Newsletters

  • Careers

    DGC is looking for talented professionals to join our team.
    Learn more 

    Working Environment

    Life @ DGC

    Benefits

    Professional Development

    Student Resources

    View Open Positions

  • Contact Us

    Send a Message

    Office Locations & Directions

  • Client Portal
  • LinkedIn
  • Twitter
  • Facebook
DGC and PKF O'Connor Davies Join Forces

Effective January 1, 2022 DGC merged with PKF O’Connor Davies (PKFOD), the 27th largest accounting and advisory firm in the U.S. Click here for more information.

Perspectives

Categories

  • All
  • Articles & Podcasts
  • Case Studies
  • Newsletters
Popular Tags
  • COVID-1992,
  • Coronavirus89,
  • Cybersecurity47,
  • IT Risk Assurance and Advisory40,
  • Tax Reform40,
  • Business Tax36,
  • Private Client36,
  • Paycheck Protection Program32,
  • PPP Loans30,
  • Podcasts26,

Spotlight on ISO 27001

11/16/2021 Articles & Podcasts

Companies have many choices when it comes to demonstrating their information security capabilities to customers and prospects. For service organizations, we often talk about the System and Organization Control (SOC 2) examination. However, another prolific standard is an excellent option for companies that don't fit a service organization mold: ISO 27001.

ISO 27001 is a leading, widely recognized international standard and certification regime focused on how to manage information security. The standard is published and maintained by ISO, the International Standards Organization, in Geneva, Switzerland. ISO 27001's objective is to help organizations build and maintain an Information Security Management System (ISMS), which will help to ensure the confidentiality, integrity, and availability of a company's information systems.

Complying with ISO 27001 involves several steps:

  • Defining the scope of the certification effort
  • Developing policies and procedures
  • Defining your information security objectives
  • Selecting and implementing your information security controls
  • Developing a security risk assessment and risk treatment process
  • Developing and executing an internal audit program
  • Building an information security performance monitoring and measurement process
  • Defining and documenting standards for professional competence
  • Building and executing a management review process
  • Creating and enabling a continuous improvement process
  • Documenting and remediating non-conformities to the ISO 27001 standard
  • Engaging an ISO 27001 Certification Body to perform your certification

ISO 27001 accredited certifications can only be performed by a Certification Body (CB) accredited by a national accreditation body, like ANAB in the United States. These certificates are valid for three years and involve annual surveillance assessments to ensure the organization remains in compliance with the standard.

The ISO 27001 standard is comprised of ten clauses, seven of which represent the "magic clauses" that comprise the required components of an ISMS that an organization is required to define and implement. Those clauses require:

  • Defining and documenting the context of the organization
  • Obtaining leadership support for the program
  • Conducting planning for the implementation and maintenance of the ISMS
  • Providing support for the implementation and maintenance of the ISMS
  • Documenting and implementing standards for the operation of the ISMS
  • Implementing a mechanism to evaluate the performance and efficacy of the ISMS
  • Implementing a continuous improvement program

These clauses and the requirements therein represent the standard. Also provided within ISO 27001 are the Annex A information security controls, which are 114 controls, suggested by ISO, to meet the requirements in the seven "magic clauses." It is not required for organizations to adopt these controls. However, if the controls are not adopted, the organization must explain how or why the Annex A controls are not applicable.

An ISO 27001 start-to-finish implementation program can take anywhere from three months to a year to complete, depending on the scope of the ISMS, the size and complexity of the organization, and the maturity of the existing information security program.

To ensure that your ISO 27001 compliance effort succeeds, consider engaging with certified experts. DGC’s IT Risk Assurance & Advisory team members are ISO 27001 Lead Implementer-certified and have experience both implementing the standard and performing internal audits of the standard.

DGC’s IT Risk Assurance & Advisory practice offers a range of IT Audit, compliance, and cyber & information security services that can help identify, evaluate, measure and manage compliance and cybersecurity risks. Our professionals are trained to identify areas of exposure and recommend size-appropriate, cost-conscious corrective actions. For more information, contact a member of your DGC client service team or Nick DeLena, CISSP, CISA, CRISC, CDPSE at 781-937-5191 / ndelena@dgccpa.com.

If you would like to get alerts and insights like this sent directly to your inbox, sign up here.

Articles & Podcasts
    Cybersecurity, ISO 27001, IT Risk Assurance and Advisory

About the Author

Nick DeLena, CISSP, CISA, CRISC, CDPSE
Nick DeLena, CISSP, CISA, CRISC, CDPSE Partner
More Articles by Nick
Author Profile

About the Author

Nick DeLena, CISSP, CISA, CRISC, CDPSE
Nick DeLena, CISSP, CISA, CRISC, CDPSE Partner
More Articles by Nick
Author Profile
DGC’s IT Risk Team Discovers Previously Unknown Vulnerability in Autodesk Software During Penetration Testing for Client 8/11/2021
How Your Organization Can Avoid Denial of Cyber Insurance Coverage 7/16/2021
Helping Defense Contractors Thrive: CMMC and DoD Cybersecurity Compliance 6/21/2021
  • Home
  • About Us
  • Contact Us
  • Careers
  • Privacy
  • Disclaimer
  • Newsletter
  • LinkedIn
  • Twitter
  • Facebook
© 2022 DGC, a division of PKF O'Connor Davies.
All Rights Reserved.

Get alerts and insights
sent directly to your inbox.