Cyber Assurance & Compliance

IASME Cyber Assurance Is Available In Two Levels

Verified Assessment and Audited

The IASME Cyber Assurance certification includes GDPR requirements and is available in two levels: Level 1 Verified Assessment and Level 2 Audited. There is a prerequisite to applying for IASME Cyber Assurance; you must hold a valid Cyber Essentials certificate throughout your IASME Cyber Assurance certification.

It is a great fit for organisations that want ISO 27001, but realise it's a long journey and use IASME as a significant stepping stone towards ISO 27001, as shown below there a mappings from Cyber Assurance to these other standards, meaning that the work is reusable towards those standards.

For  Level 1 - verified assessment,  organisations access a secure portal to answer around 160 questions about their security. The assessment is marked by a Certification Body and a pass or fail is returned to the organisation. For Level 2 - audited,  an independent assessor conducts an on-site audit of the controls, processes and procedures covered in the IASME Cyber Assurance standard. The audited version gives a higher level of assurance and is pass or fail.

The Government's Procurement Bill 2022 is passing through the parliamentary process and is due to come into law. It seeks to reform the UK's public procurement regime to create a fairer and more transparent system. It also aims to support businesses by making public procurement more accessible to small businesses, and voluntary, charitable and social enterprises, by enabling them to compete for public contracts. Over 95% of all organisations in the UK are SMEs, many of whom are the most innovative organisations in their sector. The new procurement bill is a positive sign that SMEs are being welcomed and encouraged into supply chains and allowed to compete with larger organisations for business.

A wide range of industry sectors now accept the audited IASME Cyber Assurance certification as an alternative to ISO 27001 for small companies. This is a significant step towards reducing barriers to entry for smaller organisations in a supply chain as IASME Cyber Assurance gives SMEs a legitimate way to prove their compliance.

IASME Cyber Assurance maps to the majority of the ISO27001 / ISO27002 controls at achieved or partially achieved level, the mapping between IASME Governance and ISO27001 can be found here

The UK General Data Protection Regulation (GDPR) sets out seven key principles that should lie at the heart of an approach to processing personal data. Accountability is the seventh principle and the one that demonstrates that businesses are doing the right thing. IASME cyber Assurance aligns with the vast majority of the ICO's Accountability Framework, the mapping between IASME Governance and the ICO's Accountability Framework is here

Originally published in 2012 and is now used by a majority of the FTSE350 aligns directly with 10 Steps to Cyber Security on all topics, the mapping between IASME Governance and the 10 Steps Guidance is available here

The mapping between IASME Governance and the Network & Information Systems Regulations (NIS) Cyber Assessment Framework (CAF) can be found here

IASME-Cyber-Assurance-Level-One-Scheme-Logo
Self-Assessed

IASME Cyber Assurance (Level 1)

IASME Cyber Assurance is risk based and includes key aspects of security such as incident response, asset management, people management, physical controls and GDPR compliance.

This certification allows smaller companies to demonstrate their level of cyber security and information governance for a realistic cost.  It indicates that they are taking further steps to properly protect their customers' information and also meeting the data protection requirements of GDPR.

The IASME Governance standard is aligned to a similar set of controls as ISO 27001* but is more practical, affordable and achievable for small and medium sized organisations to implement.

This standard, complements and builds on Cyber Essentials.  Indeed, it even includes a Cyber Essentials assessment and the GDPR requirements.  Whereas Cyber Essentials checks the technical controls, this standard also includes a check against key governance aspects, such as

  • Risk assessment and management
  • Training and managing people
  • Change management
  • Monitoring
  • Incident response and business continuity

Level 1 certification is the first step along the certification pathway for IASME Cyber Assurance.  For the Level 1 certification, organisations are given access to a secure portal to complete their application and provide details against the Question Set.

IASME-Cyber-Assurance-Level-Two-Scheme-Logo
Independently Verified Audited Self-Assessment

IASME Cyber Assurance (Level 2)

You will need to have completed the IASME Cyber Assurance Level 1 certification before you can progress to the Level 2 audit.

IASME Cyber Assurance Level 2 involves an audit of your processes, procedures and controls required by the standard. The audit is independent and conducted by an IASME Certification Body and Assessor.

A wide range of UK and International industry sectors now accept the Level 2 audited IASME Cyber Assurance certification as an alternative to other international standards.

The standard covers 14 themes across 5 areas of control.

IASME Thirteen Themes