Keybridge prepares ISO 27001 certification in Iraq and Kurdistan.
Manage information risks, access responsibilities and incident response. We confirm the scope and the buyer’s stated requirements before preparation starts. Buyer acceptance depends on the certificate scope, issuing body and the requirements set by the buyer. We review those requirements before preparation.
ISO 27001 Information security management systems
ISO 27001 at a glance
- Published
- October 2022. ISO/IEC 27001:2022 is the current edition. Amendment 1 of February 2024 added the climate action wording to clauses 4.1 and 4.2.
- Structure
- Annex SL high level structure. 10 clauses, and clauses 4 to 10 carry the auditable requirements. Annex A adds 93 controls in four themes.
- Certifiable
- Yes. The company is certified for a defined scope of systems, services and sites. There is no certificate for a product or a person under this standard.
- Certificate validity
- The assessment body confirms the applicable schedule and continuing requirements for your scope.
- Surveillance
- The assessment body confirms the applicable schedule and continuing requirements for your scope.
- Audit days, 10 to 50 people
- The assessment body confirms the applicable schedule and continuing requirements for your scope.
- What the scope covers
- Only the sites and activities written into the scope. Anything left out of it is not covered.
- What the certificate says
- The company name, the standard, the scope and the dates the certificate runs.
- Language of the system
- We write the policies and procedures in Arabic, Kurdish or English. Asset registers, access reviews and incident logs are usually kept in English because the tools are in English.
What ISO 27001 is
ISO/IEC 27001:2022 is the international standard for an information security management system. It asks a company to list what it holds and what it runs, assess the risk to that information, decide which controls it applies, and record what happens when something goes wrong. It applies to a defined scope of systems, services and sites.
What the standard requires
- Clauses 1 to 3 cover scope, normative references and terms. Clauses 4 to 10 are the requirements an auditor checks, and Annex A lists the 93 controls.
- Clause 4, context. List the parties that matter, then fix the scope of the security system by site, service, system and type of data.
- Clause 5, leadership. Management signs the information security policy and names who owns risk, who approves access and who runs incident response.
- Clause 6, planning. Run the risk assessment, write the risk treatment plan, and produce the Statement of Applicability that accepts or excludes each of the 93 Annex A controls with a written reason.
- Clause 7, support. Competence records for the IT and security roles, awareness training for every employee, and version control over the documented information.
- Clause 8, operation. Carry out the risk treatment plan, keep the risk assessment current, and control the changes and the suppliers that touch the scope.
- Clause 9, performance evaluation. Measure the security objectives, run internal audits against every clause and every applied control, and hold a management review.
- Clause 10, improvement. Log every nonconformity and every security incident, find the cause, correct it, and show the correction worked.
- Annex A, 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. The auditor samples the controls the Statement of Applicability declares in use.
Who needs ISO 27001 in Iraq and Kurdistan
The buyers that ask for ISO 27001
| Buyer or list | What they ask for |
|---|---|
| Central Bank of Iraq licensed payment companies | Check the financing or procurement conditions for the relevant project. Confirm whether certification is requested rather than assuming it from the sector. |
| Telecom operators | Review this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately. |
| UN agencies through UNGM | Check the individual procurement notice for the required certificate and scope. Registration on UNGM does not replace the tender’s qualification criteria. |
| KRG Approved Suppliers Center | Check the current registration instructions for your activity and category. Confirm whether this standard is requested and which issuing bodies are accepted. |
| Federal Ministry of Planning | Check the current registration instructions for your activity and category. Confirm whether this standard is requested and which issuing bodies are accepted. |
| Kurdistan and Basra operators | Review this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately. |
| Gulf buyers | Review this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately. |
| Foreign parent companies and lenders | Check the financing or procurement conditions for the relevant project. Confirm whether certification is requested rather than assuming it from the sector. |
What shapes your investment
- Number of sites and whether the auditor has to travel to Erbil, Sulaymaniyah, Baghdad or Basra.
- Size of the scope, counted in systems, services, databases and locations rather than in staff alone.
- Headcount inside the scope, which sets how many auditor days the audit takes.
- Number of Annex A controls declared in use in the Statement of Applicability and how much evidence each one needs.
- Whether cloud services and outsourced hosting sit inside the scope, because each provider has to be assessed.
- Languages the documentation is written in.
- How much usable documentation, logging and monitoring already exists in the company.
- The date the documents are needed by.
- Whether ISO/IEC 27001 is built alone or together with ISO 9001 and ISO/IEC 20000-1 as one system; the certification body determines the audit time.
The proposal names the scope, the deliverables and the dates before work starts.