07011011237  |  info@aceictconsult.comOffices in Abuja and Lagos, Nigeria
ACE ICT Consult logoACE ICT ConsultBook a Consultation

Preparing for ISO/IEC 27001:2022: The Practical Roadmap

Demystifying the revised 93 controls, ISMS scoping, risk treatment, and policy architecture to pass Stage 1 and Stage 2 certification audits without operational friction.

Governance & ISO StandardsPublished: January 26, 202610 Min ReadBy ACE GRC Advisory Practice

Achieving accredited certification under ISO/IEC 27001:2022—the premier global benchmark for Information Security Management Systems (ISMS)—is no longer just an accolade for tech startups. In Nigeria and across the African continent, institutional clients, corporate boards, and regulatory bodies (including the Central Bank of Nigeria and the NDPC) increasingly mandate ISO 27001 certification before awarding enterprise contracts or issuing operating licenses.

Yet many corporate implementations collapse under unnecessary complexity. Organizations attempt to boil the ocean, treating ISO 27001 as an academic documentation exercise rather than an operational security culture.

Understanding the 2022 Revision: 93 Controls Across 4 Themes

The previous 2013 edition featured 114 controls arranged in 14 domains. The ISO/IEC 27001:2022 standard streamlined this into 93 controls consolidated under 4 logical themes:

The 5 Implementation Phases of a Successful ISMS

Phase 1: Defining the ISMS Scope

The most consequential decision occurs on day one: defining the boundary of your ISMS. If you try to certify every business unit, field branch, and physical office in one go, costs spiral. Instead, focus the initial scope on:

  • Revenue-generating digital platforms and core customer databases.
  • The central data center and primary corporate headquarters where data is processed.
  • Core technological personnel (engineers, sysadmins, DevOps, support leads).

Phase 2: Risk Assessment & The Statement of Applicability (SoA)

ISO 27001 is risk-based, not prescriptive. You must evaluate threats to your assets (Confidentiality, Integrity, Availability) and select appropriate controls. This culminates in the Statement of Applicability (SoA)—the single most scrutinized document during external audits. The SoA explicitly lists:

  • Which of the 93 Annex A controls are selected and why.
  • Which controls are excluded, with rigorous technical justifications (e.g., excluding physical manufacturing controls if your entire platform is cloud-hosted on AWS or Azure).
  • The current implementation status of each chosen control.

Phase 3: Developing the Mandatory Policy Architecture

External auditors look for operationalized, signed policies, not generic templates downloaded from the internet. The five mandatory policy documents scrutinized first include:

  1. Information Security Policy: Endorsed by the Board of Directors or Managing Director.
  2. Access Control Policy: Defining password standards, MFA, PAM, and user access recertifications.
  3. Incident Management Procedure: Outlining incident severity levels, containment steps, and statutory 72-hour reporting channels under NDPA 2023.
  4. Business Continuity & Disaster Recovery Plan: Defining RTO and RPO targets paired with tested recovery procedures.
  5. Third-Party / Supplier Security Policy: Mandating right-to-audit and data protection covenants for all cloud and IT vendors.

Phase 4: Operational Embedding & The Internal Audit

Before inviting an accredited certification body (such as BSI, PECB, or Bureau Veritas), the ISMS must have run for at least 3 months to generate operational evidence:

  • Tickets showing change management approvals.
  • Logs demonstrating monthly vulnerability scans and patch updates.
  • Attendance logs and quiz results from employee security awareness training.
  • A formal Internal Audit conducted by qualified internal or external auditors across every clause and control.
  • Documented Management Review Meeting (MRM) minutes chaired by executive leadership.

Phase 5: Stage 1 and Stage 2 External Audits

External certification occurs in two sequential steps:

  • Stage 1 Audit (Readiness Review): The certification body inspects your scope, mandatory documentation, risk assessment, and SoA to verify readiness. Any major gaps must be resolved before proceeding.
  • Stage 2 Audit (Certification Inspection): Auditors conduct extensive walkthroughs, interview employees, and inspect real-time server configurations and logs to verify controls operate effectively. Upon success, the official ISO 27001 certificate is issued for a 3-year cycle with annual surveillance audits.

Planning your ISO 27001 certification journey?

Speak to our certified lead implementers and auditors today.

Book an ISO Consultation