Compliance and regulation

ISO/IEC 27001

Implementation and certification of the information security management system.

What it involves

What we do

We support your organisation from scope to certificate: context, risks, Annex A controls, documentation, internal audit and preparation for the certification audit.

What's included

  • Definition of scope and context
  • Risk analysis and statement of applicability
  • Implementation of Annex A controls (ISO 27001:2022)
  • Documentation set and training
  • Internal audit and management review
  • Support during the certification audit and ongoing maintenance

Who it's for

  • Companies that need certification as a commercial differentiator
  • ICT service and SaaS providers
  • Organisations that want to structure their security around a recognised standard

Deliverables

  • Documented ISMS
  • Statement of applicability
  • Internal audit report
  • Risk treatment plan

Reference frameworks and standards

ISO/IEC 27001:2022ISO/IEC 27002ISO 27005

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does ISO/IEC 27001 fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.