Loading
Global Energy Up is an independent certification body for management systems and a validation and verification body for greenhouse-gas information. We audit and decide; we do not consult.
A control that nobody tested is an assumption, not a control.
ISO/IEC 27001 certification demonstrates that an organization assesses its information-security risks and treats them through selected controls, justified in a Statement of Applicability.
Who it is for. Technology and cloud providers, financial services, healthcare, government contractors and any organization holding sensitive information.
Each area above is assessed on objective evidence — records, interviews and direct observation of work.
Audit time is determined under ISO/IEC 27006-1:2024, based on the number of persons doing work under the organization’s control and the complexity of the ISMS. Remote auditing never reduces the required audit time.
Review of documentation, readiness and scope, and planning of Stage 2.
On-site evaluation of implementation and effectiveness; findings are recorded.
An independent decision, then annual surveillance through the three-year cycle.
The edition audited will be announced when the scheme opens.
Where the system is integrated with others, the standards can be audited together in one visit; duration is calculated for each standard and then adjusted for the actual degree of integration.