What Are The Steps Involved In Getting ISO 27001 Certified
ISO 27001 certification can initially seem complex, particularly for Australian organisations that do not have dedicated information security or compliance specialists. However, the process becomes much easier to manage when it is divided into clear stages, and the information security management system is designed around the way the organisation already operates.
In simple terms, getting ISO 27001 certified in Australia involves defining the scope of your information security management system, identifying security risks, developing and implementing appropriate policies and controls, conducting an internal audit, completing management review and corrective actions, and undergoing an independent certification audit.
A well-designed system should not create unnecessary paperwork or force employees to follow processes that do not suit the business. The objective is to establish a practical framework that protects information, supports Australian customer and contractual requirements, and can be maintained over time.
Understanding ISO 27001 Certification
SO 27001 is an internationally recognised standard for information security management systems, or ISMS.
An ISMS helps organisations identify and manage risks involving customer data, employee records, intellectual property, financial information, business systems, and third-party information.
Certification demonstrates that documented processes and security controls are in place to manage these risks consistently. It can help organisations:
- Meet customer or contractual requirements
- Qualify for government and commercial contracts
- Strengthen customer confidence
- Demonstrate information security capability
- Support business growth
For Australian organisations, ISO 27001 certification can assure customers, government agencies, tendering authorities, business partners, and supply-chain stakeholders. It is especially relevant to IT providers, government contractors, engineering firms, manufacturers, laboratories, professional services, and other organisations handling confidential information.
Step 1: Understand Why Your Organisation Needs Certification
Before creating policies or introducing new controls, clarify why your Australian organisation is seeking ISO 27001 certification.
Some organisations pursue certification because an Australian government agency, major customer, tendering authority, or supply-chain partner requires evidence of formal information security management. Others use certification to strengthen customer confidence, compete for new contracts, demonstrate that they take information security seriously, or support expansion into national and international markets.
Understanding the main objective helps determine:
- The certification deadline
- The parts of the organisation that need to be included
- The resources required
- The level of support needed
- The expectations of customers and other interested parties
Leadership commitment is also important at this stage. Senior management should understand the purpose of the ISMS, allocate the necessary time and resources, and assign clear responsibilities for its implementation.
Without clear leadership support, the project may be treated as a documentation exercise rather than a functioning management system.
Step 2: Define the Scope of the ISMS
The next step is to define the scope of the information security management system.
The scope establishes which parts of the organisation will be covered by certification. It may include the entire organisation or focus on a particular department, service, office, technology platform, or business function.
When defining the scope, consider:
- Physical office locations
- Remote working arrangements
- Business departments
- Information assets
- Technology systems
- Services provided to customers
- Employees and contractors
- Suppliers and outsourced providers
- Legal and contractual requirements
For Australian organisations, the scope should account for all relevant offices, remote workers, cloud systems, outsourced providers, and business activities included in the certification. It should also reflect applicable Australian legal, regulatory, customer, and contractual obligations.
A clearly defined scope helps ensure that the certification project remains focused.
If the scope is unnecessarily broad, implementation may become more expensive and time-consuming. If it is too narrow, important information, systems, or processes may be left outside the ISMS.
The scope should make sense in relation to the organisation’s services, operating environment, and customer expectations.
Step 3: Conduct an ISO 27001 Gap Analysis
A gap analysis compares the organisation’s existing information security practices with the requirements of ISO 27001.
Its purpose is to identify what is already working, what needs improvement, and what is missing.
A gap analysis may examine:
- Existing information security policies
- Risk management processes
- Access controls
- Asset management
- Employee security awareness
- Incident reporting procedures
- Supplier management
- Business continuity arrangements
- Internal monitoring
- Existing audit processes
- Documentation and record-keeping
Many organisations already have useful security practices in place. However, these practices may not be formally documented, consistently followed, or supported by sufficient evidence.
A detailed gap analysis can help prevent unnecessary duplication and provide a practical action plan based on risk, priority, and certification deadlines.
We provide ISO 27001 gap analysis services to help Australian organisations understand their current position, identify missing requirements, and develop a practical action plan for certification.
Step 4: Complete an Information Security Risk Assessment
Risk assessment is a central part of ISO 27001.
The organisation must identify the information it needs to protect and evaluate the threats and vulnerabilities that could affect it.
The risk assessment process may consider:
- Customer and employee information
- Business-critical systems
- Intellectual property
- Financial records
- Cloud services
- Physical equipment
- Supplier access
- Cybersecurity threats
- Human error
- Unauthorised access
- Data loss
- System outages
Each risk should be evaluated according to its likelihood and potential impact on the organisation.
The purpose is not to remove every possible risk. Instead, the organisation needs a consistent process for understanding its risks and deciding how they should be managed.
The risk assessment should reflect the organisation’s actual operations. A generic risk register copied from another business may overlook important threats or include risks that are not relevant.
Step 5: Develop a Risk Treatment Plan
After risks have been identified and evaluated, the organisation must decide how each risk will be treated.
Common risk treatment options include:
- Reducing the risk by introducing controls
- Avoiding the activity that creates the risk
- Transferring or sharing the risk
- Accepting the risk when it is within approved limits
The selected actions should be documented in a risk treatment plan.
For example, an organisation may reduce the risk of unauthorised access by introducing stronger access controls, reviewing user permissions, and providing security awareness training.
The treatment plan should clearly identify:
- The risk being addressed
- The action required
- The person responsible
- The intended completion date
- The control being implemented
- The status of the action
This creates accountability and gives the organisation a clear implementation roadmap.
Step 6: Prepare the Statement of Applicability
The Statement of Applicability, commonly known as the SoA, is one of the key documents required for an ISO 27001 management system.
It records the information security controls the organisation has selected and explains why particular controls are included or excluded.
The Statement of Applicability should align with the following:
- The organisation’s risk assessment
- Its risk treatment decisions
- Customer requirements
- Contractual obligations
- Applicable laws and regulations
- The organisation’s operating environment
The SoA provides auditors with a clear overview of the controls that form part of the organisation’s ISMS.
It should not be treated as a generic checklist. The selected controls need to be relevant to the organisation’s actual risks and circumstances.
Step 7: Develop the Required Policies and Documentation
The organisation must prepare documentation that explains how its ISMS operates.
Depending on the organisation, this may include:
- Information security policies
- Risk assessment procedures
- Risk treatment plans
- The Statement of Applicability
- Access control procedures
- Incident management procedures
- Supplier security requirements
- Asset management records
- Business continuity arrangements
- Roles and responsibilities
- Employee training records
- Internal audit reports
Documentation should accurately reflect what the organisation does in practice.
This is where many template-based systems create problems. A generic policy may include processes, responsibilities, or controls that do not suit the organisation. Employees are then expected to change their work simply to match the documents.
At Compliancehelp, we use a bespoke approach rather than forcing Australian organisations into a cookie-cutter system. Wherever practical, we develop documentation around the organisation’s existing operations, responsibilities, and working practices. This can reduce unnecessary implementation work and make ongoing compliance easier.
Step 8: Implement the ISMS
Policies alone are not enough to achieve certification. The organisation must demonstrate that the documented processes and controls have been implemented.
Implementation may involve:
- Applying access controls
- Reviewing user accounts and permissions
- Establishing incident reporting processes
- Completing employee training
- Managing supplier risks
- Testing backup and recovery procedures
- Recording security events
- Updating contracts or employment requirements
- Monitoring security performance
- Maintaining evidence that procedures are followed
Employees should understand their responsibilities and how information security applies to their daily work.
Training may cover password practices, phishing awareness, handling confidential information, recognising phishing attempts, reporting incidents, and complying with access-control requirements.
Implementation is usually easier when policies are designed around existing business processes. A bespoke system limits unnecessary disruption and helps employees understand how ISO 27001 fits into their roles.
Step 9: Conduct an Internal Audit
Before the external certification audit, the organisation must review whether its ISMS has been effectively implemented.
An internal audit examines whether the management system meets ISO 27001 requirements, aligns with the organisation’s documented processes, and is being followed in practice.
Internal audit activities may include:
- Reviewing documents and records
- Interviewing employees
- Examining completed risk assessments
- Checking whether controls are operating effectively
- Reviewing incident records
- Evaluating employee training evidence
- Identifying nonconformities
- Recommending corrective actions
The auditor should be sufficiently independent of the activities being reviewed.
The purpose of the internal audit is not to assign blame. It allows the organisation to identify weaknesses, address gaps, and improve the ISMS before the certification body conducts its assessment.
Organisations that do not have suitable internal resources may engage an experienced consultant to conduct the internal audit.
Step 10: Complete Management Review and Corrective Actions
After the internal audit, senior management should formally review the ISMS to confirm that it remains suitable, adequate, and effective.
The management review allows leadership to assess the overall performance of the system and determine whether the organisation is ready to proceed with certification.
The review may consider:
- Internal audit findings
- Information security objectives
- Monitoring and measurement results
- Security incidents and nonconformities
- The status of previous corrective actions
- Changes affecting the organisation or its ISMS
- Feedback from customers and other interested parties
- Risk assessment and risk treatment results
- Opportunities for continual improvement
- Resource or training requirements
Any nonconformities identified during the internal audit should be investigated and addressed through appropriate corrective action. The organisation should identify the cause of each issue, implement the required changes, and retain evidence showing that the action has been completed.
The management review and corrective action process confirms that the ISMS has been evaluated internally and is ready for independent assessment.
Step 11: Select an Accredited Certification Body and Complete the Stage 1 Audit
ISO 27001 certification is issued by an independent certification body. Australian organisations should select an appropriately accredited certification body with suitable industry experience, auditor availability, geographic coverage, and the ability to assess their Australian operations.
When comparing certification bodies, consider:
- Accreditation
- Auditor experience
- Audit costs
- Availability
- Industry familiarity
- Geographic coverage
- Customer requirements
- Ongoing surveillance arrangements
The certification body should be contacted early when the organisation has a customer, tender, or contractual deadline, as auditor availability can affect the overall certification schedule.
The consultant who helps prepare the organisation for certification must remain separate from the certification body conducting the independent assessment.
The Stage 1 audit focuses primarily on the organisation’s documentation and readiness for the full certification assessment. The auditor may review:
- The ISMS scope
- Information security policies
- Risk assessment records
- The risk treatment plan
- The Statement of Applicability
- Internal audit results
- Management review records
- Corrective-action evidence
- Evidence that the ISMS has been implemented
The auditor will determine whether the organisation is ready to proceed to the Stage 2 audit. Any concerns identified during Stage 1 should be addressed before the next assessment.
Step 12: Complete the Stage 2 Certification Audit
The Stage 2 audit assesses whether the ISMS has been fully implemented and is operating effectively.
The auditor may:
- Interview employees and managers
- Review policies and records
- Examine selected information security controls
- Check that documented procedures are followed
- Review evidence of employee training
- Evaluate risk treatment activities
- Review internal audit and management review records
- Assess corrective actions
- Evaluate the overall effectiveness of the ISMS
The organisation must demonstrate that its policies are not merely documents created for the audit. Employees should understand their responsibilities, controls should be operating as intended, and records should show that required activities have been completed.
If nonconformities are identified, the organisation may need to complete corrective actions and provide supporting evidence before certification can be issued.
Once the certification body is satisfied that the organisation meets the requirements of ISO 27001, it can recommend the organisation for certification.
Make ISO 27001 Certification Easier in Australia
The most effective ISO 27001 system is one that fits your organisation rather than forcing your organisation to follow a generic template.
We have been helping organisations prepare for ISO certification since 2000. Our bespoke approach is designed to reduce unnecessary implementation work, simplify the certification process, and make ongoing compliance easier.
Our ISO 27001 support may include:
- Gap analysis
- Risk assessment and risk treatment
- Policies and procedures
- Statement of Applicability development
- Implementation assistance
- Internal audits
- Certification preparation
- Ongoing compliance support
Ready to simplify your path to ISO 27001 certification? Contact us to schedule a consultation and receive practical, tailored guidance for your organisation.

