Compliance answers

ISO 27001 and CyberSecure Canada FAQ

Clear answers about ISO 27001 implementation and maintenance, CyberSecure Canada preparation, evidence, and certification readiness.

What is ISO 27001?

ISO/IEC 27001 is an international standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

How do you implement ISO 27001?

Define the ISMS scope, assess information-security risks, select and operate controls, document risk treatment, collect evidence, perform internal audit and management review, and address findings before certification audit.

How do you maintain ISO 27001 after certification?

Maintain the ISMS through recurring risk reviews, control ownership, evidence updates, incident and change tracking, internal audits, management reviews, corrective actions, and continual improvement.

What is CyberSecure Canada?

CyberSecure Canada is a Canadian cybersecurity certification program for small and medium-sized organizations. It focuses on baseline security practices that help organizations improve their cybersecurity posture and demonstrate that core safeguards are in place.

How do you prepare for CyberSecure Canada certification?

Start with a baseline assessment against current requirements, identify gaps, assign accountable owners, implement and document safeguards, collect operating evidence, and prepare for the applicable certification process.

How long does CyberSecure Canada certification take?

The timeline depends on current practices, scope, gap count, evidence quality, owner availability, and the current certification process. No software can guarantee a certification timeline.

What evidence is needed for CyberSecure Canada?

Common evidence can include policies, procedures, asset and risk records, training records, access reviews, security configuration evidence, incident records, backup evidence, and proof that required practices are operating. Confirm current expectations with the certification body or program authority.

What does MapleGRC do for ISO 27001 and CyberSecure Canada?

MapleGRC is self-service GRC software that connects governance, risk, controls, policies, evidence, assessments, remediation, and reporting for implementation, maintenance, and readiness work.

Does MapleGRC provide certification or professional consulting?

No. MapleGRC is software, not a certification body or professional-services consultancy. It helps organizations manage their own cybersecurity governance, risk, compliance, evidence, and readiness work.