1. Home
  2. Blog
  3. Compliance
ISO 27001:2022 certification in Bangladesh – Oriole Security

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It does not prescribe a single technology. It requires that an organisation identify its information risks and manage them through a documented, audited, continuously improved system.

What certification actually involves

  1. Scope definition — which parts of the business, which locations, which systems.
  2. Risk assessment — identify information assets, threats and vulnerabilities, and score the risk.
  3. Statement of Applicability — go through every Annex A control, decide whether it applies, and justify every exclusion.
  4. Implementation — policies, procedures and technical controls, plus the evidence that they are followed.
  5. Internal audit and management review — prove the system is being run, not just written.
  6. External audit — Stage 1 (documentation) then Stage 2 (evidence), by an accredited certification body, followed by annual surveillance audits and recertification every three years.

What changed in the 2022 revision

Annex A was restructured from 114 controls in 14 domains to 93 controls in 4 themes — organisational, people, physical and technological. Eleven controls are genuinely new and they tell you where the standard's authors think the risk has moved:

  • Threat intelligence
  • Information security for use of cloud services
  • ICT readiness for business continuity
  • Physical security monitoring
  • Configuration management
  • Information deletion
  • Data masking
  • Data leakage prevention
  • Monitoring activities
  • Web filtering
  • Secure coding

Organisations still certified against the 2013 version have had to transition. If a vendor tells you they are "ISO 27001 certified", ask which version and ask to see the certificate — it names the certification body, the scope and the expiry date.

Why it matters when choosing a security vendor

A penetration testing firm handles the most sensitive information you have: the exact list of ways to break into your systems. Before you hand that over, it is fair to ask how the vendor protects it.

  • Report handling. Where are draft and final reports stored, who can read them, how long are they retained, how are they destroyed?
  • Access control. Do testers use individual accounts with MFA? Is access revoked when an engagement ends?
  • Personnel. Are testers background-checked and bound by confidentiality agreements?
  • Incident response. What happens if the vendor itself is breached, and how quickly are you told?

ISO 27001 certification means an independent auditor has checked the answers rather than taking the vendor's word for it.

Verify, do not assume. Ask for the certificate, check the scope covers the service you are buying, and confirm the certification body is accredited. A logo on a website is not evidence.

Is certification worth it for your own organisation?

It is worth it when customers or regulators demand it, when you sell to enterprise or overseas clients, or when you handle data whose loss would end the business. It is a poor first step if basic controls — MFA, patching, backups, logging — are not yet in place. Build the controls, then certify the system that manages them.

Oriole Security is ISO 27001:2022 certified and our consultants help clients in Bangladesh prepare for their own certification. See how we work or get in touch.

Ready to secure your business?

Oriole Security is your cybersecurity partner in Bangladesh. Get a free 30-minute consultation with our ISO 27001:2022 certified experts.

Get Free Consultation