ISO/IEC 27701 is a data privacy extension to ISO/IEC 27001 that provides organizations with recommendations and guidance to help them comply with the General Data Protection Regulation (GDPR) and other data privacy regulations. ISPMS stands for Information Security Privacy Management System and provides a framework for PII Controllers and Processors to manage data privacy.
Normative Reference
ISO/IEC 27701 normative references are as follows:
We provide certification service against the internationally recognized standard ISO/IEC 27701. The benefits of ISO/IEC 27701 certification are:
Information Security Certification Body (ISCB) of CyberSecurity Malaysia undertakes to manage impartiality and to ensure that certification activities undertaken are conducted in an impartial manner. ISCB does not permit commercial, financial or other pressures to compromise its commitment to impartiality. The credibility, integrity and objectivity of a certification is fundamental to our client’s needs and for those that subsequently rely on it. The management team at ISCB has committed to ensuring that any threats to the impartiality and confidentiality in the certification activities are managed robustly and pro-actively. ISCB has defined and maintains a strict impartiality procedure and monitors this closely through an impartiality committee made up of members representing key interested parties. ISCB is also committed to identifying and assessing risks in all related certification activities which may result in a conflict of interest or pose a threat to impartiality. It is necessary to cover all possible sources of conflict of interests, regardless of their origin.
The steps towards achieving ISO/IEC 27701 certification are shown below :
Application
Organisations should complete an application form and provide relevant supporting information to request for quotation. Kindly note that the quotation for audit days will vary depending on the scope of certification, the size of the organisation, complexity of the scope etc. Application Review The application will be reviewed by Certification Body (CB) to ensure information about the organisation and its management system is sufficient and the CB has the competence and ability to perform the certification activity. Based on this review, the CB will either accept or decline the application.
Stage 1 Audit
The purpose of Stage 1 Audit is to verify that the organisation’s management system is implemented and the organisation’s preparedness of Stage 2 audit. CB will review the organisation’s management system documented information and obtain the necessary information regarding the scope of management system.
Stage 2 Audit
Stage 2 audit evaluates the implementation, including effectiveness of the organisation’s ISMS. Where Non-conformities and Opportunities for Improvements are observed, the CB will formally document them. The organisation should provide an appropriate set of corrective actions to resolve the identified non-conformities.
Certification Decision
All information and audit evidence gathered during Stage 1 and Stage 2 audits will be analysed in order to review the audit findings and agree on the audit conclusions. The CB will make the final decision after all non-conformities have been resolved. The decision include granting or refusing certification, expanding or reducing the scope of certification.
Surveillance/Recertification
Surveillance audits are conducted periodically for the CB to maintain confidence that the organisation’s certified management system continues to fulfil the standard requirements. Recertification audit will be conducted if the organisation wishes to renew its certification. The purpose of the recertification audit is to confirm the continued conformity and effectiveness of the management system, and its continued relevance and applicability for the scope of certification.
The total fee will vary depending on the organisation's scope and size. Shown here is the general guideline:
| Fee Category | Detailed Fee |
| Application Fee | RM 500.00 |
| Initial Certification Fee |
Adequacy Audit |
| Compliance Audit | |
| Annual Fee | RM 1000.00 |
| Surveillance Fees |
Surveillance 1 |
| Surveillance 2 |
The total audit fee includes the professional fee, the number of auditor and the required number of audit days. This will be determined based on client organization desired certification scope.
Fees shown are not inclusive of incidental cost which covers accommodation and travel (where applicable). These fees will be charged directly to the organisation.
For any enquiry please contact:
enquiry@cybersecurity.my
COPYRIGHT © CYBERSECURITY MALAYSIA
Warna Teks
A A A ASaiz Teks
A+ A A-