Audits and IS audit for ISO 27001 and IT-Grundschutz
You operate an ISMS (information security management system) and need an ISO 27001 audit, a certification on the basis of IT-Grundschutz or an IS audit (IS-Revision)? We clarify the evidence required and plan the audit in the appropriate procedure.
BSI audit team leaders for ISO 27001 on the basis of IT-Grundschutz
ISO 27001 Lead Auditors on the team
Certification to ISO 27001 and IT-Grundschutz: independent and transparent.
Your situation
Your ISMS is to be certified or reviewed in an IS audit – and you are looking for experienced auditors?
You have built an ISMS to ISO 27001 or based on BSI IT-Grundschutz and now need the evidence: initial certification or recertification to ISO 27001, an ISO 27001 certification on the basis of IT-Grundschutz, an IS audit without a certificate or, as a vehicle registration office, evidence of compliance with the i-Kfz minimum security requirements of the KBA (German Federal Motor Transport Authority).
Which procedure fits depends on who requires the evidence. Hardly anyone undergoes an IT-Grundschutz certification voluntarily – which makes it all the more important that the audit delivers more than just the certificate.
This is where we come in: our certified auditors for ISO 27001 on the basis of IT-Grundschutz, IS auditors and ISO 27001 Lead Auditors audit thoroughly and objectively. We care about the quality of our audits: we plan enough time so that findings are well founded and help you in substance. If we have previously advised you, for example on implementing IT-Grundschutz, we do not carry out the certification audit – the certification scheme rules this out.
Testing portfolio
Which audits we carry out
For organisations that already operate an ISMS and need the evidence.
ISMS certification and IS audit
Certification audit for ISO 27001 on the basis of IT-Grundschutz
Attestation for Basic Protection under IT-Grundschutz
IS audit and IS short audit according to the BSI guideline
ISO 27001 audit (initial certification and recertification) with partner certification bodies
Four audit procedures, one standard: added value in substance, not a mandatory appointment
You get initial certification and recertification audits for ISO 27001 on the basis of IT-Grundschutz, IS audits or audits of the KBA's i-Kfz minimum security requirements, carried out by certified auditors, IS auditors and ISO 27001 Lead Auditors. The audits are planned so that findings are well founded and help you in substance; for IT-Grundschutz, the BSI decides on the certificate.
ISO 27001 audit, IT-Grundschutz certification, IS audit and i-Kfz audit follow different procedures. We first clarify which evidence you need and then audit according to the scheme prescribed in each case.
01
ISO 27001 on the basis of IT-Grundschutz
You need to have your organisation or part of it certified based on BSI IT-Grundschutz? Our experienced, certified auditors for ISO 27001 on the basis of IT-Grundschutz carry out the audit and submit the audit report to the BSI, which decides on certification.
Our standard: a professional and objective audit atmosphere, and added value in substance from the audit – not just the certificate at the end.
Audit report for the BSI
An audit report as the basis for the BSI's certification decision – with findings you can also learn from in substance.
02
IS audit according to the BSI guideline
Your ISMS must meet the requirements of BSI IT-Grundschutz but does not need certification? Then an IS audit according to the BSI guideline for IS audits (Leitfaden IS-Revision) demonstrates the security level achieved. There are different levels; in most cases, an IS short audit is sufficient. Our IS auditors ensure:
a thorough review along the topics described in the guideline
an honest and open assessment, mapped to your processes and your documentation
visibility of critical areas requiring urgent action
a clear assessment and a jointly defined set of next steps
IS audit report
An assessment of the security level achieved, with prioritised next steps.
03
ISO 27001 certification
You have built an ISMS to ISO 27001 and want to make your level visible with a certificate? We work with several certification bodies and carry out ISO 27001 audits in a pragmatic, goal-oriented and open way – including recertifications.
Our auditors know not only the standards but also the technologies and processes needed to reach a meaningful assessment. The certification body decides on the certificate.
04
i-Kfz: minimum security requirements of the KBA
Your vehicle registration office is subject to the KBA's minimum security requirements for internet-based vehicle registration (MSA-i-Kfz)? We have already audited a high double-digit number of registration offices across Germany. Our audit approaches are efficient, transparent and easy for you to prepare for:
i-Kfz audit / IS short audit
IS penetration test of the specialised application systems
IS penetration test of the connectors
IS web check of the specialised applications
Our expertise
Since December 2011, secuvera has been recognised by the BSI as a certified IT security service provider for IS audit. Several experienced, certified auditors for ISO 27001 on the basis of IT-Grundschutz, IS auditors and ISO 27001 Lead Auditors work in our company. For ISO 27001 audits, we work with several certification bodies.
Under the KBA's i-Kfz minimum security requirements, we have already audited a high double-digit number of registration offices across Germany – organisationally by audit or IS short audit and technically by IS penetration test and IS web check.
Because audits and penetration tests come from one company, you receive coordinated organisational and technical audits from a single source.
Getting started
Define the type of audit and the certification body
Clarify the evidence you need
Tell us the underlying standard, your scope and the planned certification or audit date. Existing certificates and previous audit findings are also part of the preparation.
Agree audit procedure and responsibilities
We discuss the appropriate type of audit, the documents required and the cooperation with the certification body.
Type of audit and certification body chosen to match your goal.
Audit and certification decision
The audit and the certification decision are separate. The scope of the audit and responsibilities are agreed according to the evidence required.
Questions about ISO 27001 audits, IT-Grundschutz and IS audit
What is the difference between an IS audit and a certification?
An IS audit assesses the security level according to the BSI guideline for IS audits, without requiring certification. There are different levels; an IS short audit is often an option. A certification, by contrast, follows the procedure of the responsible certification body.
Does secuvera carry out audits to ISO 27001 and on the basis of IT-Grundschutz?
Yes. Our team includes ISO 27001 Lead Auditors as well as certified auditors for ISO 27001 on the basis of IT-Grundschutz. Which audit framework applies depends on the evidence required and the certification procedure.
Can we also request a recertification?
Yes. For planning, the existing certificate, scope, previous findings and the intended date are important. We coordinate the audit and the cooperation with the responsible certification body.
Who issues the ISO 27001 certificate?
The responsible certification body decides on certification. secuvera provides the agreed audit services. The audit result and the certification decision are separate steps.
Can secuvera first advise us and then certify us?
Not for the same organisation. Under the certification scheme, consulting or coaching and the certification audit cannot be combined. If we have advised you, another body carries out the audit – and vice versa.