ISO 27001 consulting & implementation

Design and implement an ISO/IEC 27001 Information Security Management System and prepare for certification audit.

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). Certification requires an accredited body to assess your ISMS against the standard in a two-stage audit and then at surveillance audits over a three-year cycle.

A consulting engagement builds the ISMS with your team rather than handing over a binder of templates, so the management system reflects how your organisation actually works and holds up under audit.

What the engagement covers

Scope and context

Agree the ISMS scope, interested parties, and how information security objectives map to business objectives.

Risk assessment and treatment

Establish a repeatable risk assessment method, run the first assessment, and produce a risk treatment plan and Statement of Applicability against Annex A.

Policies and controls

Draft and adapt the policies, procedures and controls needed for your context, and support the teams that have to operate them.

Evidence and operation

Set up evidence collection, internal audit, management review and corrective action so the ISMS is demonstrably operating before the audit.

Certification audit support

Prepare for and attend the Stage 1 and Stage 2 audits with the certification body, and help close any findings.

Common questions

Talk through ISO 27001 for your team

A short call to confirm scope, timeline and a firm price — before you commit to anything.