ISO 27001 from gap analysis to certification
An information security management system that works in the business: risk work, policies, controls, a Statement of Applicability, internal audit and preparation for certification.
Who it is for and when
Suits organisations heading for ISO 27001 certification, or that need a management system they can show a customer or owner, and that want it to work in daily operations rather than sit in a binder.
- A customer or owner requires ISO 27001, or a management system you can demonstrate.
- You have policies but no coherent management system.
- Risk work lives in a spreadsheet and is rarely updated.
- You want to certify but do not know what remains or in what order.
What we do
- Gap analysis and scope. We establish the scope of the management system and assess the current state against the standard, requirement by requirement, so the work starts at the right end.
- Risk method and risk work. A risk method the business can actually use, with risk criteria, a risk register and risk treatment plans that can be kept current.
- Policies and controls. Policies, routines and the control structure are developed from your risk profile, with a Statement of Applicability showing which controls apply and why the others do not.
- Implementation in the business. Controls are implemented where the work is actually done, with training and with the evidence the audit will ask for.
- Internal audit, management review and pre-audit. We carry out the internal audit and management review and run a pre-audit, so that nonconformities are found before the certification audit.
What you get
- A management system with policies, risk method and control structure
- A Statement of Applicability with a rationale per control
- A completed internal audit and management review
- A pre-audit with an action plan ahead of the certification audit
- Handover so that you can maintain the management system yourselves
Scope and price
A project that normally runs over several months, depending on the size of the organisation, the scope of the management system and how much is in place when we start.
The price varies from engagement to engagement and depends on the scope above. You get an estimated cost proposal and, where possible, a fixed price. The certification audit is carried out by an accredited certification body and their fees fall outside the engagement.
How it works
- A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.
Frequently asked questions
How long does it take to become certified?
It is driven by how much is in place, how large the scope is and how quickly the business can implement the changes. We set a timeline in the gap analysis, and it only holds if the resources are there.
Do you certify us?
No. Certification is carried out by an accredited and independent certification body. We build the management system, get you ready and can run the pre-audit before they arrive.
Do all Annex A controls have to apply to us?
No. The Statement of Applicability is precisely the document where you justify which controls are applicable and why the others are not. That rationale is what the auditor reads.
Would you like a management system that holds up in an audit?
Contact us