The CSM27001 scheme provides an audit and certification services based on the ISO/IEC 27001 standard. The ISO/IEC 27001 standard specifies the requirements for establishing, operating, monitoring, reviewing, maintaining and improving an organisation’s Information Security Management System.
With the Scheme, various information security goals, such as protecting the con?dentiality, availability, authenticity, non-repudiation, and integrity of information handled by the organisation could be achieved through a certification programme based on the internationally recognised standard ISO/IEC 27001.
CyberSecurity Malaysia undertakes to manage impartiality and to ensure that certification activities undertaken are conducted in an impartial manner.
We do not permit commercial, financial or other pressures to compromise our commitment to impartiality. The credibility, integrity and objectivity of a certification is fundamental to our client’s needs and for those that subsequently rely on it.
We commit to ensure that any threats to the impartiality and confidentiality in the certification activities are managed robustly and pro-actively.
We practice impartiality and monitors this closely through an impartiality committee made up of members representing key interested parties.
We also commit to identify and assess risks in related certification activities which may result in a conflict of interest or pose a threat to impartiality. The risk assessment covers possible sources of conflict of interests, regardless of their origin.
The steps towards achieving ISO/IEC 27001 certification are shown below:
Application
Organisations should complete an application form and provide relevant supporting information to request for quotation. Kindly note that the quotation for audit days will vary depending on the scope of certification, the size of the organisation, complexity of the scope etc.
Application Review
The application will be reviewed by Certification Body (CB) to ensure information about the organisation and its management system is sufficient and the CB has the competence and ability to perform the certification activity. Based on this review, the CB will either accept or decline the application.
Stage 1 Audit
The purpose of Stage 1 Audit is to verify that the organisation’s management system is implemented and the organisation’s preparedness of Stage 2 audit. CB will review the organisation’s management system documented information and obtain the necessary information regarding the scope of management system.
Stage 2 Audit
Stage 2 audit evaluates the implementation, including effectiveness of the organisation’s ISMS. Where Non-conformities and Opportunities for Improvements are observed, the CB will formally document them. The organisation should provide an appropriate set of corrective actions to resolve the identified non-conformities.
Certification Decision
All information and audit evidence gathered during Stage 1 and Stage 2 audits will be analysed in order to review the audit findings and agree on the audit conclusions. The CB will make the final decision after all non-conformities have been resolved. The decision include granting or refusing certification, expanding or reducing the scope of certification.
Surveillance/Recertification
Surveillance audits are conducted periodically for the CB to maintain confidence that the organisation’s certified management system continues to fulfil the standard requirements. Recertification audit will be conducted if the organisation wishes to renew its certification. The purpose of the recertification audit is to confirm the continued conformity and effectiveness of the management system, and its continued relevance and applicability for the scope of certification.
Click here to download the CSM27001 Application Form.
The total fee will vary depending on the organisation's scope and size. Shown here is the general guideline:
Evaluation Assurance Level | Certification Assurance Fees |
EAL1 | RM 16,000 |
Application Fee | RM 500.00 |
Initial Certification Fee |
Adequacy Audit |
Compliance Audit | |
Annual Fee | RM 1000.00 |
Surveillance Fees |
Surveillance 1 |
Surveillance 2 |
The total audit fee includes the professional fee, the number of auditor and the required number of audit days. This will be determined based on client organization desired certification scope.
Fees shown are not inclusive of incidental cost which covers accommodation and travel (where applicable). These fees will be charged directly to the organisation.
For any enquiry please contact:
enquiry@cybersecurity.my
COPYRIGHT © CYBERSECURITY MALAYSIA
Warna Teks
A A A ASaiz Teks
A+ A A-