Standards

Achieve and maintain ISO 27001 certification

ISMS risk assessment, Statement of Applicability, Annex A controls, and certification audits in one workspace.

Moduulit 4
Tyypillinen kesto 6 to 12 months

The situation

ISO 27001 is the international standard for information security management systems (ISMS). Certification is awarded by an accredited certification body after evidence that your organisation identifies information security risks, selects and implements controls, and maintains a Statement of Applicability (SoA) mapping Annex A controls to your risk treatment decisions. It is not a checklist of 93 controls applied blindly: the risk assessment drives which controls matter.

Most organisations move through ISMS scope and asset identification, information security risk assessment and treatment, SoA and Annex A control implementation, internal audit and management review, then stage 1 documentation review and stage 2 certification audit, followed by surveillance audits. Elevale does not award ISO 27001 certification. It gives security, IT, and leadership teams one structured workspace to manage that journey and keep evidence current between audit cycles.

Information security risk assessment

ISO 27001 clause 6.1.2 requires a systematic information security risk assessment: identify risks to confidentiality, integrity, and availability of information within ISMS scope, assess likelihood and impact, and evaluate risk levels. The risk assessment methodology must be documented and consistently applied.

Risk treatment options include modifying risk, retaining it with justification, avoiding it, or sharing it. Treatment decisions feed directly into control selection. Certification body auditors challenge risk assessments that look copied from templates without connection to your actual systems, data flows, and threat landscape. Elevale links risk registers and treatment plans to pathway stages and control evidence.

Statement of Applicability and Annex A controls

The Statement of Applicability (SoA) is a mandatory document listing all Annex A controls from ISO 27001:2022, stating whether each is applicable, and providing justification for inclusion or exclusion. For applicable controls, the SoA references how each is implemented.

Annex A contains 93 controls organised into organisational, people, physical, and technological themes. You do not implement all 93 by default: the risk assessment determines which controls are needed. Auditors sample SoA entries against live evidence: access management, cryptography, supplier relationships, incident management, and business continuity. Elevale keeps the SoA connected to risk treatment decisions and control evidence so surveillance audits start from a maintained record.

Why spreadsheets and point tools fall short

Risk registers live in spreadsheets disconnected from the Statement of Applicability. Security policies sit in a document library while control evidence (access reviews, change records, penetration tests) sits in ticketing tools and vendor portals. When the certification body returns for surveillance, teams rebuild evidence packs from exports instead of pulling from live systems.

Generic compliance platforms break ISO 27001 into numbered modules that do not match how security teams actually run risk assessment and control operation. Without a single record linking risks, SoA decisions, Annex A controls, and audit findings, certification preparation repeats the same manual reconciliation every cycle.

How Elevale supports your ISO 27001 journey

Elevale gives security, IT, and leadership teams one workspace to manage the ISO 27001 journey from risk assessment through SoA, internal audit, stage 1, stage 2, and ongoing surveillance. Certification Pathway maps each stage with linked evidence, named owners, and review dates that stay current as systems, vendors, and threat landscapes change.

Company Wiki stores information security policies, risk assessment methodology, and the Statement of Applicability with version history linked to pathway stages. Task Management connects risk treatment actions, control testing, access reviews, incident follow-ups, and internal audit findings so ISMS maintenance does not depend on disconnected security folders.

Certification Pathway

Track risk assessment, SoA, and certification audit stages

Certification Pathway structures your ISO 27001 journey by certification stage, not by generic compliance modules. Scope definition, risk assessment, SoA, internal audit, stage 1, stage 2, and surveillance each link evidence, tasks, owners, and review dates in one maintained record.

Company Wiki

ISMS policies and SoA linked to Annex A control evidence

Company Wiki stores your information security policy, risk assessment methodology, Statement of Applicability, and control procedures with version history. Link wiki pages directly to Annex A controls and pathway stages so auditors trace risk treatment decisions to operational evidence.

Task Management

Risk treatment and control testing stay on schedule

Task Management connects risk treatment actions, recurring control tests, access reviews, vendor assessments, incident investigations, and internal audit findings. Control operation stays visible through surveillance so evidence does not age between audit cycles.

A practical rhythm for ISO 27001

  1. Define scope and identify assets. Confirm ISMS scope across systems, locations, and services, identify information assets and interested party requirements, and open the ISO 27001 pathway from the certification library.
  2. Assess and treat risks. Run the information security risk assessment using your documented methodology, evaluate risks to confidentiality, integrity, and availability, and document risk treatment decisions that drive control selection.
  3. Build the SoA and implement controls. Publish the Statement of Applicability listing Annex A controls with applicability justification, implement selected controls, and link evidence from policies, technical systems, and operational records.
  4. Run internal audit and management review. Complete the internal audit programme against ISO 27001 and your ISMS requirements, record findings and corrective actions, and hold management review before the certification body assessment.
  5. Complete stage 1, stage 2, and surveillance. Present documented information at stage 1, demonstrate control effectiveness at stage 2, then maintain risk assessments, SoA, control testing, and surveillance dates year round.

What changes when your ISO 27001 journey runs in one system

Teams working toward ISO 27001 in Elevale spend less time assembling security binders and more time operating controls consistently. Risk treatment decisions stay linked to the SoA and Annex A evidence, and surveillance dates sit beside the proof certification bodies already reviewed.

When systems, vendors, or threat landscapes change, linked pathway stages update with them. The next risk assessment refresh, SoA review, or surveillance visit starts from a maintained workspace, not a folder rebuilt from ticket exports.

Getting started

Select the ISO 27001 pathway from the certification library, define ISMS scope with security and leadership stakeholders, and link risk registers and policies from your wiki. Start your 14-day free trial or explore Certification Pathway to see how certification and surveillance stay aligned.

Näin saat tämän sertifikaatin

What is ISO 27001 certification?

ISO 27001 is the international standard for information security management systems. Certification is awarded by an accredited certification body after stage 1 and stage 2 audits confirm your ISMS meets the standard. Core requirements include information security risk assessment, risk treatment, a Statement of Applicability mapping Annex A controls, and continual improvement. Elevale does not award ISO 27001 certification.

What is a Statement of Applicability (SoA)?

The SoA is a mandatory ISMS document listing all Annex A controls from ISO 27001:2022, stating whether each control is applicable, and providing justification for inclusion or exclusion. For applicable controls, it references how each is implemented. The SoA must align with your risk assessment and risk treatment decisions. Certification body auditors sample SoA entries against live control evidence. Elevale links the SoA to risk registers and pathway stages.

How does risk assessment drive Annex A controls?

ISO 27001 requires a systematic information security risk assessment before selecting controls. You identify risks to confidentiality, integrity, and availability, assess and evaluate them, then choose treatment options. Annex A controls are selected based on risks identified, not applied as a blanket checklist. The SoA documents which of the 93 controls are applicable and why. Elevale structures the journey around risk assessment and control treatment, not generic numbered modules.

What is the difference between stage 1 and stage 2 audits?

Stage 1 reviews ISMS documentation: scope, policy, risk assessment methodology, risk register, Statement of Applicability, and procedures. Stage 2 is the detailed audit where auditors verify that risk treatment and Annex A controls operate effectively in practice, sampling systems, access management, incident response, and supplier controls. Both are required for initial certification, with annual surveillance and triennial recertification.

Can Elevale help with ISO 27001 certification?

Yes. Elevale gives security and IT teams one workspace to manage ISMS scope, information security risk assessments, the Statement of Applicability, Annex A control evidence, internal audits, and certification body audit preparation. Certification Pathway connects each stage to linked evidence, tasks, and review dates. Elevale supports your programme but does not perform audits or issue certificates.

Aloita

Your next quarter deserves action, not another spreadsheet.

Start your 14-day free trial and connect direction, OKRs, team alignment, and live intelligence in one command centre. No setup circus. No app-switching.

14-day free trial Plans for every team size Cancel anytime