ISO/IEC 27001 – Information Security Management System (ISMS) certification

Every organisation’s most fundamental business processes are built on data and information. This includes key data such as the confidential details of customers and partners, information relating to various products, services, orders and internal processes, as well as a wide range of other information connected to the company’s know-how.

IAF CertSearch – A global database containing all accredited management system certificates

The IAF CertSearch database was created by the IAF (International Accreditation Forum). The purpose of IAF CertSearch is to provide accurate data on accredited (management system) certificates issued by certification bodies accredited by internationally recognised accreditation bodies that are signatories to the IAF MLA.

The database allows you to check whether:

  • whether their suppliers and partners hold certification,
  • whether the certificate(s) are valid,
  • whether the certification body issuing the certificate is accredited,
  • whether the certifying body is accredited to issue certificates in accordance with the relevant standard.

 

All certificates issued by IWS Certification can be found at https://iafcertsearch.org in the IAF CertSearch database, which is available via the link.

The IWS certificate is valuable. Choose our certification services

Change to the standard!

Information on transitioning to the new MSZ ISO/IEC 27001:2023 standard 

The International Organisation for Standardisation (ISO)/International Electrotechnical Commission (IEC), the ISO/IEC JTC, has revised the structure of the ISO/IEC 27001/27002 audit framework and published the new ISO/IEC 27001:2022 (as well as ISO/IEC 27002:2022) standard.

the ISO/IEC 27002:2022 standard.
The Hungarian translation of the standard was also published on 1 June 2023:
MSZ ISO/IEC 27001:2023 standard, Information security, cybersecurity and privacy protection. Information security management systems. Requirements.

Following the revision of the standard in 2022, the International Accreditation Forum (IAF) has published its transition guide „TRANSITION REQUIREMENTS FOR ISO/IEC 27001:2022 (IAF MD 26)” was published. In line with this, the National Accreditation Authority Transition Timetable too.

Taking the above guidelines into account, IWS Certification, as a certification body accredited by NAH, provides the following information regarding the transition to the new standard and its accredited certification services:

  • Our clients who hold MSZ ISO/IEC 27001:2014 certification must complete the transition to the new standard and obtain certification by 31 October 2025 at the latest.
  • After 30 April 2024, certification and recertification/renewal may only be carried out in accordance with the new standard.
  • If you wish to carry out the migration as part of a compliance audit, the additional audit time required to verify the migration is at least one day.
  • In the event of a transition during a renewal audit, the minimum additional audit time required is 0.5 days

Please feel free to contact us regarding the new standard as well!

Regulated information security

Any disruption affecting the quality, quantity, accuracy or availability of this information poses a business risk. Threats can originate from both outside and within an organisation; they may be accidental or deliberate.

Due to weaknesses in the security system, information may be compromised, disclosed, accessed by unauthorised persons, or even destroyed.

In light of all this, ensuring the integrity, confidentiality and availability of data, and preventing breaches and data loss, is a task of critical importance.

Certification of the Regulated Information Security Management System (IBIR)

A solution that works for both the organisation in question and its partners means the effective management of information security risks and processes.

The establishment and operation of an Information Security Management System in accordance with the ISO/IEC 27001 standard serves to enhance the security of companies’ business-critical information, IT systems and processes.

Why not let us handle your IBIR certification tasks?

What does the new standard cover, and what are the benefits for organisations?

The purpose of the Information Security Management System in accordance with the ISO/IEC 27001 standard

The implementation of the system is a compilation of an information asset inventory by means of a begins with a risk-based assessment, which assessment must be carried out in relation to all of the organisation’s systems on the basis of three criteria (CIA classification):

  • Confidentiality: the regulation of access rights and access levels for data and information stored in the electronic information system.
  • Integrity: the content and attributes of the data correspond to expectations, including that the information is authentic (originates from the expected source), non-repudiable (its origin can be verified), and that the components of the electronic information system can be used for their intended purpose.
  • Availability: To ensure that electronic information systems are accessible to authorised persons and that the data processed therein can be utilised.

The ISO/IEC 27001 standard provides an up-to-date management tool for protecting data and information as assets, managing the associated processes, identifying threats, addressing internal and external challenges, and ensuring continuous improvement.

Just as a fire safety system reduces the risks associated with fire – partly through prevention and partly by preventing the fire from escalating – so too does an Information Security Management System reduce the risks associated with information breaches. Although this may require investment, effort, attention and the deployment of physical systems, the level of investment – in the case of a well-designed system – will be proportionate to the risks, but significantly lower than the potential cost of any damage that might occur.

The fundamental principle of the standard is continuous improvement, just as in quality management (ISO 9001, IATF 16949), occupational health and safety (ISO 45001) and environmental management (ISO 14001 and EMAS) standards, so its approach is closely linked to those.

About the ISO/IEC 27001 standard in general

The ISO/IEC 27001 standard was published by the International Organization for Standardization (ISO). In the years following the standard’s publication, the number of certified companies worldwide has already exceeded tens of thousands and has continued to grow ever since.

The standard covers the following areas:

  • safety regulations;
  • security organisation;
  • checking and classifying assets and equipment;
  • personal safety;
  • physical and environmental safety;
  • communication and operational management;
  • access rights verification;
  • system development and maintenance;
  • business continuity management;
  • compliance.

Operating in accordance with the standard enables domestic companies to prepare for the challenges posed by the spread of IT systems and the risks associated with electronic data storage.

Why not let us handle your IBIR certification tasks?

What are the benefits?

Certification provides feedback on whether our overall information security measures comply with the requirements of the ISO/IEC 27001 standard. The implementation and certification of ISO/IEC 27001 can also change corporate culture:

  • reduces fraud, as well as those managed and stored by the company, its employees and its partners the risk of loss or disclosure of confidential data;
  • makes relationships more secure, builds trust among customers;
  • where external partners and IT service providers are engaged provides a framework for the company’s external and internal information and data security strategy;
  • as planned ensures business continuity „in the event of an IT emergency”;
  • because it is a management tool, the senior and middle management are able to keep coordinated data protection processes under control without possessing in-depth specialist knowledge in specific areas (e.g. asset protection, IT networks, etc.).


An audit in accordance with the standard involves a thorough review of all aspects of IT security, the from the analysis of information processes starting with the through data loss unauthorised access and through virus attacks right up to e-commerce, the until unauthorised entry and the until disaster response.

implementation of the system significantly in the longer term can reduce costs, as this can reduce downtime and make information flows and IT security more coordinated.

Security of information technology systems – ISO/IEC 20000

In addition to information and data security, the security of their IT systems is also important for all companies. The ISO/IEC 20000 standard focuses on the capacity of IT systems, the establishment of management levels, financial planning, software management, and thus the monitoring processes of IT systems. System implementation in accordance with the standard and the acquisition of certification, by classifying individual system components into categories (the so-called „helpdesk” approach), provides a structured and effective method for building secure IT systems and ensuring their operational capability.

Accreditation

IWS holds the internationally recognised accreditation required for its certification, issued by the National Accreditation Authority (NAH) under reference number NAH-4-0152/2022: https://www.nah.gov.hu/hu/szervezet/iws-solutions-kft-/.
This ensures that the certificate issued by IWS is widely accepted by the certified organisation both domestically (in the case of public tenders and calls for proposals) and internationally.

Why IWS?

  • We have auditors who speak both Hungarian and other languages, and we are able to conduct integrated audits of management systems compliant with ISO 9001, ISO 14001, ISO 45001, ISO 50001 and ISO/IEC 27001, even across multiple sites in different countries.
  • An accredited certificate issued by an independent certification body demonstrates a commitment to all the company’s stakeholders (employees, customers, clients, owners, etc.) and reliably demonstrates the existence of regulated data and information security measures within the company.
  • The audit we have carried out provides objective feedback the operation of the system, thereby contributing to its development and the evaluation of its results.

Who is it for?

  • industrial and manufacturing companies (chemical industry, electronics, metal and plastics processing sector, automotive industry, primarily due to product design, product know-how, processes and partners);
  • service sector (e.g. freight forwarding and logistics companies, tourism, the entertainment industry);
  • telecommunications and IT companies (software development, IT and telecommunications solutions);
  • the financial (banking) and insurance sectors;
  • the utilities and energy sector (water, gas, electricity, waste, etc.);
  • the public administration and regulatory sector (due to the processing of clients’ personal data);
  • property protection and security technology companies (security technologies);
  • healthcare sector.

IWS certification

seres

Diana Seres

Head of Certification

Aszód

Ágnes Aszódi

ISO Product Manager

ISO 9001, 14001, 27001, 45001, 50001

Tamas

Eszter Tamás

Project Manager

VCA/SCC certification

Ask for a quote!

Your message will be forwarded to the relevant department, and our colleagues will get back to you as soon as possible at the email address you provided.

Certification quote request form

Our address

2040 Budaörs (Terrapark), 14/C Puskás Tivadar Road.

Email

tanusitas@iws.hu