Skip to main content
ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS): a documented, risk-based framework for protecting the confidentiality, integrity, and availability of information. botBrains is getting ready to certify against it.
botBrains is not yet ISO 27001 certified. We are preparing our ISMS and writing these policies as part of pursuing certification, and we fully intend to get our controls attested.

Status

We’re preparing our ISMS for ISO 27001 certification. See the Certification Roadmap for the status of every standard.

Our ISMS

A single Information Security Policy sits at the top of our ISMS. Beneath it, the topic-specific policies below set the rules for each security domain, supported by the records ISO 27001 requires, including the Statement of Applicability, the risk register, and the internal audit programme.

Policies

Internal Documents

Alongside the policies above, botBrains maintains the records, registers, and procedures ISO 27001 requires. These are Company-Internal and live in the ISMS workspace in Notion, so the links below need employee access. The internal audit programme is the one record still to be established as botBrains prepares for certification.