An ISMS
someone reads.
ISO 27001 does not ask for perfect security. It asks for security that is demonstrably managed. We assess how far your organisation is from that, build the management system with you and support you through the stage 1 and stage 2 audits — documented as briefly as the standard allows.
What is included.
Gap analysis, ISMS build, support through to the audit.
Gap analysis
Every requirement in clauses 4–10 and every Annex A control: met, partial, open — with evidence.
ISMS build
Scope, risk methodology, policies, statement of applicability, management review, internal audit.
Implementation support
Schedule and track the actions from risk treatment; coach the owners.
Audit support
Preparation, attendance at stage 1 and stage 2, handling of nonconformities.
Five steps,
one deliverable.
Scoping
Define the scope and its interfaces.
Gap analysis
Analysis against the standard and Annex A.
Build
ISMS documents and processes — as lean as the standard allows.
Operation
Run risk treatment, internal audit and management review.
Audit
Select the certification body, support stage 1 and stage 2.