Abdul Munaim Dar
← Back to projects

ISO 27001 Certification

Owned the technical controls, monitoring, and audit remediation behind Allsorter's ISO 27001 certification — from Stage 1 readiness through the Stage 2 verification audit.

ISO 27001 Certification certification badge

Overview

ISO/IEC 27001 certifies an organization’s Information Security Management System (ISMS) — not a single product, but the ongoing process of identifying information security risks and running the controls that manage them. I was part of the team that took Allsorter through certification, owning the technical side: the Annex A controls that actually touch infrastructure and data, rather than the governance documents that describe them.

Architecture

Certification runs as a two-stage external audit. Stage 1 reviews the ISMS on paper — scope, risk assessment records, and the Statement of Applicability — to confirm the organization is ready. Stage 2 is the real test: the auditor samples evidence, interviews staff, and verifies that Annex A controls are actually operating, not just documented. Once both stages pass, certification holds for three years, with annual surveillance audits re-sampling roughly half of the 93 Annex A controls each cycle.

My part sat inside the Technological control theme: access control, monitoring and logging, vulnerability management, and the incident response process — the controls an auditor tests by looking at a running system, not by reading a policy.

Key decisions & tradeoffs

Controls built to survive Stage 2 sampling, not just Stage 1 review. Stage 1 checks that a control is documented; Stage 2 checks that it’s real. Priority went to the controls an auditor would actually sample against a live system — access control and logging — over ones that only needed to exist on paper.

Incident response designed to be exercised, not filed. A written IR process that’s never been run is a liability in an audit, not an asset. The process was built to be walked through before the auditor asked for it, not authored and shelved.

Closing gaps before the auditor found them. The internal gap analysis ahead of Stage 2 existed to surface exactly the findings an external assessor would — so remediation happened on our schedule, not during the audit itself.

Results

  • Allsorter holds ISO 27001 certification, verifiable via the compliance page.
  • The technical controls put in place — access control, logging, incident response — are the ones enforced day to day, not audit artifacts kept for show.
  • Certification is re-verified through annual surveillance audits, so the remediation work had to hold under repeat sampling, not just pass once.