Viewee
Start free
Pricing
Sign in
← Legal and assurance

Status: working towards an ISO/IEC 27001-aligned information security management system. Viewee is not claiming certification.

What the certification requires

ISO/IEC 27001:2022 requires an information security management system (ISMS) that identifies information-security risks, selects and operates proportionate controls, measures performance, corrects problems and improves over time. Certification is performed by an independent certification body; UKAS accredits certification bodies in the UK.

Evidence and controls we need

Current gap status

Next steps

  1. Name the ISMS sponsor and owner; define scope across Viewee's people, marketing site, SaaS, suppliers and development operations.

  2. Complete the DPIA and map legal, regulatory, customer and processor obligations.

  3. Build asset/data-flow registers, risk assessment, treatment plan and Statement of Applicability.

  4. Implement priority controls and retain operating evidence through several review cycles.

  5. Run an internal audit and management review; close corrective actions.

  6. Choose a UKAS-accredited certification body and plan Stage 1 and Stage 2 only when the ISMS is operating.

Official sources