We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

IT & ITeS companies

ISO 27001 for IT and ITeS Companies

For IT and ITeS providers, ISO 27001 is a contractual gate — client security questionnaires and RFPs assume it. The commercial risk is scoping the ISMS so narrowly that the certificate does not cover the delivery centres or services the client cares about.

What ISO 27001 requires of it & ites companies

  • An ISMS scope statement that covers the delivery locations and services clients will check, not the smallest certifiable unit.
  • Risk assessment and Statement of Applicability justifying every Annex A control included or excluded.
  • Controls operating across multi-client delivery — segregation between client environments is the control auditors probe hardest.
  • Internal audit and management review completed before the certification body arrives.
  • Supplier and sub-contractor security where delivery is partly outsourced.

Evidence assessors actually ask for

Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.

  • Scope statement, risk assessment and Statement of Applicability with justifications
  • Internal audit reports and management review minutes with decisions
  • Client environment segregation evidence — access, network and data
  • Joiner/mover/leaver records across delivery teams
  • Supplier assessments and contractual security terms

Where it & ites companies usually come unstuck

  • A certificate whose scope excludes the delivery centre serving the client asking for it.
  • Excluding Annex A controls without a defensible justification in the SoA.
  • Movers accumulating access across client accounts — the classic multi-tenant delivery finding.

Related

ISO 27001 servicesIT & ITeS sectorISO 27001 costISO 27001 vs SOC 2
Scope this engagement →What it costs
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Ready to discuss your ISO 27001 requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →