Skip to main content
REF-STR-004

Information Security Management

A comprehensive framework to manage and protect sensitive information, data, and assets, built to satisfy ISO 27001 requirements.

A steel server room door ajar in a dark corridor
Approach

Six phases to ISO 27001.

1

Gap Analysis

Identify project scope and objectives, and designate the team responsible for the ISMS rollout.

Gap Analysis Report
2

Risk Management

Build a risk framework and assess information systems, assets, and processes for vulnerabilities and threats.

Risk Methodology Asset Inventory & Valuation Risk Assessment Risk Treatment Plan
3

ISMS Requirements

Develop the core ISO 27001 documentation required for an effective management system.

Statement of Applicability Committee Charter
4

Policies & Procedures

Establish organizational policies and procedures ensuring compliance and safeguarding sensitive information.

Roles Documentation Usage Policies
5

Internal Audit

Conduct internal reviews to verify the system functions correctly and adheres to ISO 27001 requirements.

Audit Reports Corrective Action Plans
6

Certification Support

Support the external audit, provide on-site assistance, and resolve identified non-conformities.

ISO 27001 Certification
Deliverables

What you receive.

Gap Analysis Report
Information Security Risk Methodology
Asset Inventory and Valuation Report
Risk Assessment Report: management summary, detailed results, and risk register
Risk Treatment (Mitigation) Plan
Roles and Responsibilities
Statement of Applicability (SoA)
ISMS Committee Charter
Acceptable Use Policy, Access Control Security Policy, and Asset Management Policy
Internal Audit Report
Audit Findings and Corrective Action Plan (CAP)
ISO 27001 Certification Audit Report and the certificate itself
FAQ

Common questions.

Does this lead to ISO 27001 certification?

Yes. The final phase supports the external audit, provides on-site assistance, and resolves identified non-conformities, with the ISO 27001 certificate as the end deliverable.

What happens at the start of the engagement?

A gap analysis identifies project scope and objectives and designates the team responsible for the ISMS rollout, delivered as a gap analysis report.

How is risk handled?

A risk framework is built, then information systems, assets, and processes are assessed for vulnerabilities and threats. That phase produces a risk methodology, an asset inventory and valuation, a risk assessment, and a risk treatment plan.

Do you audit us before the certification body does?

Yes. An internal audit phase verifies the system functions correctly and adheres to ISO 27001 requirements, producing audit reports and corrective action plans ahead of the external audit.

Ready to scope Information Security Management?

Request an Assessment
Request an Assessment Email Us