Achieving accredited certification under ISO/IEC 27001:2022—the premier global benchmark for Information Security Management Systems (ISMS)—is no longer just an accolade for tech startups. In Nigeria and across the African continent, institutional clients, corporate boards, and regulatory bodies (including the Central Bank of Nigeria and the NDPC) increasingly mandate ISO 27001 certification before awarding enterprise contracts or issuing operating licenses.
Yet many corporate implementations collapse under unnecessary complexity. Organizations attempt to boil the ocean, treating ISO 27001 as an academic documentation exercise rather than an operational security culture.
Understanding the 2022 Revision: 93 Controls Across 4 Themes
The previous 2013 edition featured 114 controls arranged in 14 domains. The ISO/IEC 27001:2022 standard streamlined this into 93 controls consolidated under 4 logical themes:
| Theme | Total Controls | Core Security Focus Areas |
|---|---|---|
| Organizational Controls | 37 Controls | Information security policies, asset classification, cloud services usage, supplier relationships, remote working, and return of assets. |
| People Controls | 8 Controls | Pre-employment screening, confidentiality agreements, security awareness training, disciplinary actions, and reporting security events. |
| Physical Controls | 14 Controls | Physical security perimeters, entry controls, clean desk & clean screen policies, secure disposal, and equipment maintenance. |
| Technological Controls | 34 Controls | Access control, data masking, data leakage prevention (DLP), secure software development life cycle, configuration management, and threat intelligence. |
The 5 Implementation Phases of a Successful ISMS
Phase 1: Defining the ISMS Scope
The most consequential decision occurs on day one: defining the boundary of your ISMS. If you try to certify every business unit, field branch, and physical office in one go, costs spiral. Instead, focus the initial scope on:
- Revenue-generating digital platforms and core customer databases.
- The central data center and primary corporate headquarters where data is processed.
- Core technological personnel (engineers, sysadmins, DevOps, support leads).
Phase 2: Risk Assessment & The Statement of Applicability (SoA)
ISO 27001 is risk-based, not prescriptive. You must evaluate threats to your assets (Confidentiality, Integrity, Availability) and select appropriate controls. This culminates in the Statement of Applicability (SoA)—the single most scrutinized document during external audits. The SoA explicitly lists:
- Which of the 93 Annex A controls are selected and why.
- Which controls are excluded, with rigorous technical justifications (e.g., excluding physical manufacturing controls if your entire platform is cloud-hosted on AWS or Azure).
- The current implementation status of each chosen control.
Phase 3: Developing the Mandatory Policy Architecture
External auditors look for operationalized, signed policies, not generic templates downloaded from the internet. The five mandatory policy documents scrutinized first include:
- Information Security Policy: Endorsed by the Board of Directors or Managing Director.
- Access Control Policy: Defining password standards, MFA, PAM, and user access recertifications.
- Incident Management Procedure: Outlining incident severity levels, containment steps, and statutory 72-hour reporting channels under NDPA 2023.
- Business Continuity & Disaster Recovery Plan: Defining RTO and RPO targets paired with tested recovery procedures.
- Third-Party / Supplier Security Policy: Mandating right-to-audit and data protection covenants for all cloud and IT vendors.
Phase 4: Operational Embedding & The Internal Audit
Before inviting an accredited certification body (such as BSI, PECB, or Bureau Veritas), the ISMS must have run for at least 3 months to generate operational evidence:
- Tickets showing change management approvals.
- Logs demonstrating monthly vulnerability scans and patch updates.
- Attendance logs and quiz results from employee security awareness training.
- A formal Internal Audit conducted by qualified internal or external auditors across every clause and control.
- Documented Management Review Meeting (MRM) minutes chaired by executive leadership.
Phase 5: Stage 1 and Stage 2 External Audits
External certification occurs in two sequential steps:
- Stage 1 Audit (Readiness Review): The certification body inspects your scope, mandatory documentation, risk assessment, and SoA to verify readiness. Any major gaps must be resolved before proceeding.
- Stage 2 Audit (Certification Inspection): Auditors conduct extensive walkthroughs, interview employees, and inspect real-time server configurations and logs to verify controls operate effectively. Upon success, the official ISO 27001 certificate is issued for a 3-year cycle with annual surveillance audits.
About the ACE GRC Advisory Practice
ACE ICT Consult has guided leading Nigerian commercial institutions, fintechs, and government agencies to 100% first-attempt ISO/IEC 27001:2022 certification. Our certified lead implementers and auditors provide end-to-end support from gap analysis to final stage 2 audit defense.