GCQMTrust Today • Better Tomorrow

ISMS · Certification

ISO/IEC 27001:2022 Information Security Management Systems

ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining and continually improving an information security management system, protecting the confidentiality, integrity and availability of information.

Why get ISO/IEC 27001 certified in Iraq?

  • Protect customer data and meet banking, telecom and government security requirements
  • Manage cyber risk through 93 Annex A controls
  • Win contracts that require certified information security
  • Reduce the impact and likelihood of security incidents

Who it is for

Banks, payment providers, telecoms, software and IT service companies, data centres, government contractors and healthcare.

Key requirements

  • Information security policy and risk assessment methodology
  • Statement of Applicability against Annex A controls
  • Risk treatment plan and security objectives
  • Operational controls: access, cryptography, physical, supplier and incident management
  • Internal audit, management review and continual improvement

How GCQM delivers certification ISO/IEC 27001

GCQM is the exclusive agent in Iraq of Global Quality Certification Ltd (GQCL), accredited by EGAC (IAF / ILAC MRA signatory). Our Baghdad team manages your application, plans the audit and provides local auditors, while GQCL takes the impartial decision and issues the certificate, verifiable on its public register.

About our Certification service

ISO/IEC 27001 FAQs

What changed in ISO 27001:2022?
Annex A was restructured into four themes with 93 controls, adding controls for threat intelligence, cloud services, data masking and secure coding.

Get certified ISO/IEC 27001 with GCQM

Talk to our Baghdad team for a free, no-obligation quotation. We reply within one working day.