Governance and compliance
ISO 27001
From gap assessment to the audit, with a lead auditor alongside you.
What this work consists of
We build the information security management system that ISO 27001 requires and prepare your company for the certification audit: scope, risk assessment, controls, evidence, and a dress rehearsal before the auditor arrives. The work is led by a BSI-credentialed lead auditor. In practice, that means you hear during the project what the auditor would say afterward, while fixing things is still cheap.
The work starts by comparing what the company already has against what the standard requires, and the gaps come out ranked by risk and effort. Then comes implementation: policies written in the language of the people who will follow them, controls in operation, training for the teams involved, and an evidence routine with owners and frequency, so the audit never turns into a last-minute scramble.
On your side, the project needs access to the documents that already exist, time from the owners of each area for interviews and validation, and someone internal who is accountable for the project. At the end, you receive the approved document set and the Statement of Applicability with the rationale for each control. It is the first document the auditor opens.
You choose the depth. You can hire just the gap assessment and execute with your internal team, go all the way to full implementation, or stay with us through the end, with the audit rehearsal and our presence during the certification body's fieldwork. In any format, the audit and the certificate always come from the independent body you hire.
How we conduct it, stage by stage
The stages and deliverables below describe the Full compliance work modality. The other modalities appear when you request the proposal.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Implementation
We stand the controls up together with your team, write down what needs to exist on paper and train the people who will operate them. Nothing counts as implemented until it works in practice and someone on your side can sustain it.
Evidence routine
We set out how each control proves it worked, with an owner and a frequency, so the audit does not turn into a scramble.
What is not included
- The certification audit itself, which independence rules require to be performed by a certification body hired by you
- Issuing and maintaining the certificate, which belongs to the accredited body
- Day-to-day operation of the controls after implementation, which can be added as an ongoing service
- The certification body's fees, which are part of your contract with them
- Purchasing tools, licenses, or infrastructure identified in the action plan, which is your buying decision
- Technical execution of fixes in systems, which stays with your team or vendor, with the plan showing what to do and in what order
- Maintaining the management system in the following years and the surveillance audits, which follow the certification body's calendar
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.