ISO 27001 Information Security Management (ISMS) Certification
ISO 27001 information security management system certification in Colombo, Kandy and Sri Lanka. Risk assessment, SoA and Annex A controls. Accredited body.
ISO/IEC 27001 information security management system certification in Colombo, Kandy and across Sri Lanka — risk assessment, Statement of Applicability and Annex A controls audited to ISO 27001:2022 on a three-year cycle by an accredited body.
ISO/IEC 27001 specifies requirements for an information security management system: identifying what information matters, assessing the risks to it, selecting controls proportionate to those risks, and demonstrating the whole thing works. Certification is independent confirmation that it does.
The standard does not promise a risk-free environment and no honest certification body will claim otherwise. What it provides is a documented, tested basis for knowing which risks you have accepted and why.
Why Sri Lankan organisations certify
ISO 27001 is increasingly a condition of contract rather than a differentiator — in government and semi-government tenders, in financial services procurement, and in any supply relationship where a client's own security obligations extend to its vendors. It also provides the framework organisations use to demonstrate alignment with UAE information security requirements, including the Dubai Electronic Security Centre's standards and sector-specific regulatory expectations, since the control set and the evidence largely overlap.
What the standard requires
- Scope definitionWhat the ISMS covers — which information, services, locations and systems. A scope drawn too narrowly produces a certificate your client will reject as irrelevant to the service they buy.
- Risk assessmentA defined, repeatable method for identifying information security risks, assessing them consistently, and producing results that can be compared over time.
- Risk treatment and the Statement of ApplicabilityDecisions on which Annex A controls apply, which are excluded and why, and how each applicable control is implemented. The SoA is the document auditors examine most closely.
- Leadership and policyDemonstrated top management commitment, an information security policy, and assigned roles and responsibilities.
- Competence and awarenessPeople understanding their security responsibilities in the roles they actually hold, evidenced rather than assumed.
- Supplier and third-party securitySecurity requirements extended into supplier relationships and cloud services, and verified rather than contractually asserted.
- Incident managementDetection, reporting, response and learning, with evidence of incidents actually handled through the process.
- ContinuityInformation security aspects of business continuity, including redundancy of processing facilities.
- Access control and cryptographyIdentity and access management, privileged access, joiners and leavers handled promptly, and cryptographic controls applied where the risk assessment calls for them.
- Monitoring and internal auditMeasurement of control effectiveness, internal audit coverage of the whole ISMS, and management review with recorded decisions.
The 2022 revision
ISO/IEC 27001:2022 restructured Annex A substantially. The previous 114 controls across fourteen domains were consolidated into 93 controls across four themes — organisational, people, physical and technological — with eleven new controls added, including threat intelligence, cloud services security, ICT readiness for business continuity, data leakage prevention and secure coding.
Any certification now issued is against the 2022 edition. If you hold documentation, a Statement of Applicability or an internal audit programme still structured around the 2013 control set, that is the first gap a certification audit will find.
Where audits find gaps
Three recur. A Statement of Applicability that excludes controls without justification, or claims implementation the evidence does not support. Risk assessments performed once at implementation and never revisited, so the register describes an organisation that no longer exists. And supplier security managed by contract clause alone, with no verification that any supplier actually meets the requirement — increasingly the finding that matters most, given how much processing sits with third parties.
The certification process
Stage 1 reviews the documented ISMS, confirms the scope, and examines the risk assessment and Statement of Applicability in detail — because every control decision downstream depends on those being sound. Stage 2 tests implementation: whether controls operate as the SoA claims, whether monitoring produces real data, how incidents were actually handled, and whether personnel can describe their responsibilities. The certificate runs three years with annual surveillance and recertification before expiry.
Who certifies
- IT service providers, software companies and managed service providers
- Banking, insurance and financial services
- Government entities and their technology suppliers
- Healthcare organisations handling patient data
- Data centres, hosting and cloud providers
- Telecommunications operators
- Any organisation whose clients impose security requirements by contract
Scope and integration
The certificate states the scope, and clients read it. A scope covering head office IT does not cover the platform your client is buying. ISO 27001 shares its high-level structure with ISO 9001 and ISO 22301, so where more than one is held, integrated auditing covers the common clauses once rather than repeating them.
Our role and its limits
ITMAD is an accredited certification body. Under ISO/IEC 17021-1 we cannot design, implement or consult on the management system we certify, and we do not perform penetration testing, security consultancy or gap remediation for organisations we certify. We provide the audit and the certification decision, plus optional pre-assessment that identifies gaps without prescribing how you close them.
What you receive
- Stage 1 report identifying readiness gaps before the main audit
- Stage 2 audit report with findings supported by objective evidence
- Non-conformities classified by severity with defined response timescales
- Certificate of registration stating your certified scope
- Certification mark for use under our mark and seal policy
- Annual surveillance audits and reports through the three-year cycle