GLOBAL

Loading

Global Energy Up is an independent certification body for management systems and a validation and verification body for greenhouse-gas information. We audit and decide; we do not consult.

Information security management

ISO/IEC 27001:2022
Information security management

A control that nobody tested is an assumption, not a control.

ISO/IEC 27001 certification demonstrates that an organization assesses its information-security risks and treats them through selected controls, justified in a Statement of Applicability.

Who it is for. Technology and cloud providers, financial services, healthcare, government contractors and any organization holding sensitive information.

  • Scope of the ISMS and its interfaces and dependencies
  • Information-security risk assessment and risk treatment
  • Statement of Applicability against the Annex A controls
  • Organizational, people, physical and technological controls in operation
  • Monitoring, internal audit and management review
  • Nonconformity, corrective action and improvement
Coming soon. This scheme is being prepared and is not yet open for applications. It will be listed as available once its audit-time rules are released in our certification system.

Each area above is assessed on objective evidence — records, interviews and direct observation of work.

How the audit runs

Audit time is determined under ISO/IEC 27006-1:2024, based on the number of persons doing work under the organization’s control and the complexity of the ISMS. Remote auditing never reduces the required audit time.

01.
Stage 1

Review of documentation, readiness and scope, and planning of Stage 2.

02.
Stage 2

On-site evaluation of implementation and effectiveness; findings are recorded.

03.
Decision & surveillance

An independent decision, then annual surveillance through the three-year cycle.

Edition and transition

The edition audited will be announced when the scheme opens.

Auditing with other standards

Where the system is integrated with others, the standards can be audited together in one visit; duration is calculated for each standard and then adjusted for the actual degree of integration.

  • What do I need to apply?
    Legal name, sites, scope of activities, headcount and shift pattern, outsourced processes, any existing certificate, and whether you received consultancy on the system and from whom.
  • Why do you ask about consultancy?
    Because we do not certify a system on which a body related to us provided consultancy, and every application is screened for conflicts of interest before it is accepted.
  • Will the certificate carry an accreditation mark?
    Not before accreditation is granted. Certificates are currently issued without an accreditation mark.

Start with a
written application.