Home · Compliance · ISO 27001
ISO certification · ISO 27001Information security

Keybridge prepares ISO 27001 certification in Iraq and Kurdistan.

Manage information risks, access responsibilities and incident response. We confirm the scope and the buyer’s stated requirements before preparation starts. Buyer acceptance depends on the certificate scope, issuing body and the requirements set by the buyer. We review those requirements before preparation.

ISO 27001 Information security management systems

ISO 27001 at a glance

Published
October 2022. ISO/IEC 27001:2022 is the current edition. Amendment 1 of February 2024 added the climate action wording to clauses 4.1 and 4.2.
Structure
Annex SL high level structure. 10 clauses, and clauses 4 to 10 carry the auditable requirements. Annex A adds 93 controls in four themes.
Certifiable
Yes. The company is certified for a defined scope of systems, services and sites. There is no certificate for a product or a person under this standard.
Certificate validity
The assessment body confirms the applicable schedule and continuing requirements for your scope.
Surveillance
The assessment body confirms the applicable schedule and continuing requirements for your scope.
Audit days, 10 to 50 people
The assessment body confirms the applicable schedule and continuing requirements for your scope.
What the scope covers
Only the sites and activities written into the scope. Anything left out of it is not covered.
What the certificate says
The company name, the standard, the scope and the dates the certificate runs.
Language of the system
We write the policies and procedures in Arabic, Kurdish or English. Asset registers, access reviews and incident logs are usually kept in English because the tools are in English.

What ISO 27001 is

ISO/IEC 27001:2022 is the international standard for an information security management system. It asks a company to list what it holds and what it runs, assess the risk to that information, decide which controls it applies, and record what happens when something goes wrong. It applies to a defined scope of systems, services and sites.

What the standard requires

  1. Clauses 1 to 3 cover scope, normative references and terms. Clauses 4 to 10 are the requirements an auditor checks, and Annex A lists the 93 controls.
  2. Clause 4, context. List the parties that matter, then fix the scope of the security system by site, service, system and type of data.
  3. Clause 5, leadership. Management signs the information security policy and names who owns risk, who approves access and who runs incident response.
  4. Clause 6, planning. Run the risk assessment, write the risk treatment plan, and produce the Statement of Applicability that accepts or excludes each of the 93 Annex A controls with a written reason.
  5. Clause 7, support. Competence records for the IT and security roles, awareness training for every employee, and version control over the documented information.
  6. Clause 8, operation. Carry out the risk treatment plan, keep the risk assessment current, and control the changes and the suppliers that touch the scope.
  7. Clause 9, performance evaluation. Measure the security objectives, run internal audits against every clause and every applied control, and hold a management review.
  8. Clause 10, improvement. Log every nonconformity and every security incident, find the cause, correct it, and show the correction worked.
  9. Annex A, 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. The auditor samples the controls the Statement of Applicability declares in use.

Who needs ISO 27001 in Iraq and Kurdistan

IT and managed service providersISO 27001 may be relevant to the management of this activity. Confirm the applicable scope and any buyer requirement before seeking certification.
Banks, payment and fintech companiesISO 27001 may be relevant to the management of this activity. Confirm the applicable scope and any buyer requirement before seeking certification.
Telecom operators and their contractorsISO 27001 may be relevant to the management of this activity. Confirm the applicable scope and any buyer requirement before seeking certification.
Hospitals and medical groupsPatient records sit in systems that are shared with insurers and laboratories, and every one of those links is a risk point.
Oil and gas contractors handling operator dataOperators in Kurdistan and Basra share drilling, production and commercial data with contractors and ask how it is stored and who can read it.
Software and outsourcing companies selling abroadISO 27001 may be relevant to the management of this activity. Confirm the applicable scope and any buyer requirement before seeking certification.
Government IT suppliersMinistry and KRG tenders for systems, hosting and support carry a security section that has to be answered with documents.
NGOs and UN implementing partnersGrant agreements carry data protection clauses covering beneficiary records, and the agency can ask to see the controls.

The buyers that ask for ISO 27001

Buyer or listWhat they ask for
Central Bank of Iraq licensed payment companiesCheck the financing or procurement conditions for the relevant project. Confirm whether certification is requested rather than assuming it from the sector.
Telecom operatorsReview this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately.
UN agencies through UNGMCheck the individual procurement notice for the required certificate and scope. Registration on UNGM does not replace the tender’s qualification criteria.
KRG Approved Suppliers CenterCheck the current registration instructions for your activity and category. Confirm whether this standard is requested and which issuing bodies are accepted.
Federal Ministry of PlanningCheck the current registration instructions for your activity and category. Confirm whether this standard is requested and which issuing bodies are accepted.
Kurdistan and Basra operatorsReview this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately.
Gulf buyersReview this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately.
Foreign parent companies and lendersCheck the financing or procurement conditions for the relevant project. Confirm whether certification is requested rather than assuming it from the sector.

What shapes your investment

  • Number of sites and whether the auditor has to travel to Erbil, Sulaymaniyah, Baghdad or Basra.
  • Size of the scope, counted in systems, services, databases and locations rather than in staff alone.
  • Headcount inside the scope, which sets how many auditor days the audit takes.
  • Number of Annex A controls declared in use in the Statement of Applicability and how much evidence each one needs.
  • Whether cloud services and outsourced hosting sit inside the scope, because each provider has to be assessed.
  • Languages the documentation is written in.
  • How much usable documentation, logging and monitoring already exists in the company.
  • The date the documents are needed by.
  • Whether ISO/IEC 27001 is built alone or together with ISO 9001 and ISO/IEC 20000-1 as one system; the certification body determines the audit time.

The proposal names the scope, the deliverables and the dates before work starts.