Back to Blog
ISO 27001 Implementation: What We Learned Certifying 8 Philippine Companies
technicalJanuary 15, 2025· 10 min read

ISO 27001 Implementation: What We Learned Certifying 8 Philippine Companies

ISO 27001 implementation timeline, costs, and pitfalls from an 8-month certification project.

T

TechGuru Team

TechGuru Team

ISO 27001 Implementation: What We Learned Certifying 8 Philippine Companies

A BPO company in Makati called us in January 2024. Their biggest client required ISO 27001 certification within 6 months or they would lose a $5 million contract. They had no information security program, no documentation, and no idea where to start. We helped them achieve certification in 5 months. Here is the exact roadmap we used, refined from certifying 8 Philippine companies.

What is ISO 27001?

ISO 27001 is the international standard for information security management systems (ISMS). It provides a framework for establishing, implementing, maintaining, and improving information security. Certification proves that your organization manages information security risks systematically.

The standard has two main parts:

**Clauses 4-10:** These are mandatory requirements. They cover context of the organization, leadership, planning, support, operation, performance evaluation, and improvement. Every certified organization must comply with all clauses.

**Annex A:** These are security controls. There are 93 controls organized into 4 themes: organizational (37 controls), people (8 controls), physical (14 controls), and technological (34 controls). You select controls based on your risk assessment. Not all 93 controls apply to every organization.

ISO 27001 does not tell you what security measures to implement. It tells you how to manage security systematically. The specific controls depend on your risk assessment.

Why Philippine Companies Need ISO 27001

Philippine companies pursue ISO 27001 for several reasons.

**Client Requirements.** Many multinational clients require ISO 27001 from their Philippine partners. This is especially true in BPO, financial services, and healthcare. Without certification, you cannot win or retain these contracts.

**Regulatory Compliance.** The Data Privacy Act of 2012 requires organizations to implement reasonable security measures. ISO 27001 provides a recognized framework for compliance. While not legally required, certification demonstrates due diligence.

**Competitive Advantage.** ISO 27001 differentiates Philippine companies in the global market. It proves that security is not just a checkbox but a systematic management practice.

**Insurance Benefits.** Some cyber insurance providers offer premium discounts for ISO 27001 certified organizations. The certification demonstrates that you manage security risks systematically.

Our 8-Company Certification Roadmap

We have helped 8 Philippine companies achieve ISO 27001 certification. Here is the roadmap refined from those experiences.

Phase 1: Gap Assessment (Weeks 1-3)

Before starting implementation, we assess the current state. We compare existing practices against ISO 27001 requirements and identify gaps.

The gap assessment covers:

**Organizational context:** Who are your interested parties? What are their information security requirements? What is the scope of your ISMS?

**Leadership:** Is management committed to information security? Are roles and responsibilities defined? Is there an information security policy?

**Risk management:** Do you have a risk assessment process? Are risks identified, analyzed, and treated? Is there a risk treatment plan?

**Controls:** Which Annex A controls are currently implemented? Which are missing? Which need improvement?

For our Makati BPO client, the gap assessment revealed that they had some security measures (firewall, antivirus, access controls) but no systematic management. They had no risk assessment, no documented policies, and no incident response plan.

The gap assessment typically takes 2-3 weeks. The output is a gap report that lists every requirement and whether it is met, partially met, or not met. This becomes the implementation roadmap.

Phase 2: Risk Assessment (Weeks 4-6)

Risk assessment is the foundation of ISO 27001. You must identify information assets, assess threats and vulnerabilities, evaluate risks, and define treatment plans.

We use a four-step process:

**Asset Identification:** List all information assets: systems, data, people, processes. For a BPO company, this includes client data, employee data, systems, and communication channels.

**Threat and Vulnerability Assessment:** For each asset, identify threats (malware, unauthorized access, natural disaster) and vulnerabilities (unpatched software, weak passwords, no backup). We use industry-standard threat catalogs plus client-specific risks.

**Risk Evaluation:** Calculate risk level as Likelihood x Impact. We use a 5x5 matrix: likelihood (1-5) x impact (1-5) = risk score (1-25). Risks scoring 15+ require treatment.

**Risk Treatment:** For each unacceptable risk, define a treatment plan. Options: mitigate (implement controls), transfer (insurance), accept (with management approval), or avoid (eliminate the activity).

For our Makati client, we identified 47 information assets, 120+ threats, and 35 unacceptable risks. The risk treatment plan included 80+ action items across organizational, people, physical, and technological controls.

Phase 3: Documentation (Weeks 7-10)

ISO 27001 requires documented information. We create the following documents:

**Information Security Policy:** The top-level document that states management commitment to information security. Defines scope, objectives, and roles. Typically 2-3 pages.

**Risk Assessment Methodology:** Documents how risks are assessed: asset identification, threat analysis, risk evaluation criteria, and treatment process. Typically 5-10 pages.

**Statement of Applicability (SoA):** Lists all 93 Annex A controls and explains why each is included or excluded. This is the most time-consuming document. Typically 20-30 pages.

**Risk Treatment Plan:** Documents how each unacceptable risk will be treated, who is responsible, and when it will be completed. Typically 10-15 pages.

**Procedures and Work Instructions:** Specific procedures for implementing each control. For example, access control procedure, incident response procedure, backup procedure. Typically 5-10 procedures, 2-5 pages each.

The documentation phase is the most time-consuming. For our Makati client, we created 15 documents totaling 80+ pages. The key is to document what you actually do, not what you think auditors want to see.

Phase 4: Implementation (Weeks 11-18)

This is where you implement the controls identified in your risk treatment plan. We organize implementation by control theme.

**Organizational Controls (Weeks 11-13):** Security policies, roles and responsibilities, asset management, supplier management, incident management, business continuity. We typically implement 15-20 controls in this phase.

**People Controls (Weeks 13-14):** Security awareness training, HR security (screening, terms of employment, termination). We implement 5-8 controls in this phase.

**Physical Controls (Weeks 14-15):** Physical security perimeters, secure areas, equipment security, cabling security. We implement 8-12 controls in this phase.

**Technological Controls (Weeks 15-18):** User endpoint devices, privileged access rights, information access restriction, secure authentication, cryptographic controls, security in development, vulnerability management, configuration management, information deletion, data masking, data leakage prevention, monitoring, information security testing, network security, web filtering. We implement 15-20 controls in this phase.

The implementation phase is where most organizations struggle. The key is to prioritize: implement the controls that address your highest risks first. Not all 93 controls need to be implemented at the same level of maturity.

Phase 5: Internal Audit (Week 19)

Before the certification audit, you must conduct an internal audit. This verifies that your ISMS is implemented correctly and operating effectively.

We conduct a 1-week internal audit covering:

**Documentation review:** Verify all required documents exist, are approved, and are communicated.

**Implementation review:** Verify controls are implemented as documented. Sample test 20-30 controls across all themes.

**Effectiveness review:** Verify controls are achieving their objectives. Measure key metrics: incident count, training completion rate, backup success rate.

**Non-conformance identification:** Document any findings that do not meet ISO 27001 requirements. Categorize as major or minor non-conformances.

For our Makati client, the internal audit found 5 minor non-conformances: incomplete access reviews, missing backup tests, outdated risk assessment, incomplete training records, and missing supplier assessments. We fixed all findings before the certification audit.

Phase 6: Certification Audit (Weeks 20-22)

The certification audit is conducted by an accredited certification body (CB). The audit has two stages.

**Stage 1 Audit (1 week):** The auditor reviews your documentation and assesses readiness for Stage 2. They check that your ISMS scope is appropriate, documents exist, and you are ready for full audit.

**Stage 2 Audit (1-2 weeks):** The auditor conducts a full audit of your ISMS. They interview personnel, review records, sample test controls, and verify implementation and effectiveness.

For our Makati client, the Stage 2 audit took 8 days. The auditor interviewed 25 employees, reviewed 50+ records, and tested 40+ controls. They found 2 minor non-conformances (incomplete change management records and missing disposal logs). We provided corrective actions within 30 days and received certification.

Best Practices

Based on 8 certifications, here are our top practices.

**Get management commitment early.** ISO 27001 requires leadership involvement. If management is not committed, certification will fail. We meet with the CEO in week 1 to secure commitment.

**Focus on risk, not checkbox compliance.** ISO 27001 is a risk management framework, not a checklist. Design your ISMS around your actual risks, not what you think auditors want to see.

**Involve stakeholders.** ISO 27001 affects the entire organization. Involve IT, HR, legal, operations, and business units. The ISMS is not just an IT project.

**Document what you do.** The most common audit finding is documentation that does not match reality. Document your actual practices, not aspirational practices.

**Plan for maintenance.** ISO 27001 is not a one-time project. It requires ongoing management, monitoring, and improvement. Plan for annual internal audits, management reviews, and continuous improvement.

Common Mistakes

**Mistake 1: Skipping the gap assessment.** The gap assessment identifies what you need to do. Skipping it is like navigating without a map.

**Mistake 2: Over-documenting.** ISO 27001 requires documented information, not encyclopedias. Document what is necessary for operation and audit. Excessive documentation is a maintenance burden.

**Mistake 3: Ignoring organizational culture.** ISO 27001 requires a security culture, not just controls. If employees do not understand or support security, controls will not work.

**Mistake 4: Treating it as an IT project.** ISO 27001 affects the entire organization. HR, legal, operations, and business units all have roles. IT leads, but the whole organization participates.

**Mistake 5: Not planning for post-certification.** Certification is the beginning, not the end. Plan for annual surveillance audits, continuous improvement, and ISMS maintenance.

Conclusion

ISO 27001 certification is achievable for Philippine companies. Our Makati BPO client achieved certification in 5 months, saving their $5 million contract. The key is a structured approach: gap assessment, risk assessment, documentation, implementation, internal audit, and certification audit.

The investment is significant: consulting fees, certification fees, control implementation costs, and ongoing maintenance. But the return is clear: client contracts, regulatory compliance, competitive advantage, and improved security.

If you are pursuing ISO 27001, start with a gap assessment. Understand where you are and where you need to be. Build a risk-based implementation plan. Involve the entire organization. And plan for ongoing maintenance.

ISO 27001 is not just a certification. It is a systematic approach to managing information security that protects your organization and your clients.

Want to go deeper? Explore [Protect security services](/en/products/protect), [industry solutions](/en/solutions), or [get a security assessment](/en/contact).

FAQ

**Q: How long does ISO 27001 certification take?**

A: 4-6 months for organizations with some existing security practices. 6-9 months for organizations starting from scratch. Our fastest was 4 months; our longest was 8 months.

**Q: What is the cost of ISO 27001 certification?**

A: Consulting fees: PHP 500,000-1,500,000. Certification audit fees: PHP 300,000-600,000. Control implementation: PHP 200,000-1,000,000 depending on existing controls. Total: PHP 1-3 million.

**Q: How long is ISO 27001 certification valid?**

A: 3 years, with annual surveillance audits. After 3 years, you undergo a recertification audit. Surveillance audits verify ongoing compliance and continuous improvement.

**Q: Can I implement ISO 27001 without a consultant?**

A: Yes, but it is difficult. Consultants provide expertise, experience, and objectivity. First-time implementations almost always benefit from consulting support.

**Q: What happens if I fail the certification audit?**

A: You receive a list of non-conformances. You have 30-90 days to provide corrective actions. If corrective actions are accepted, you receive certification. If not, you may need a follow-up audit. Most organizations pass with minor non-conformances.

#ISO 27001#Information Security#Compliance#Philippines#Certification

Need help with this topic?

Our experts can help you implement the right solution for your organization.

Contact Us