Planning, design, knowledge transfer and support for implementing and maintaining an Information Security Management System under the ISO/IEC 27000 framework.
Typical duration
8 to 14 months
Delivery
Blended — on site and remote
Support
SORT Redmine included
Levels
Essential · Advanced · Complete
Objective and scope
We provide specialist support and coaching in information security through a highly qualified team. Engagements can start immediately, with a blended methodology: on-site visits combined with remote work. The four phases make up the core of the ISMS implementation, common to all three service levels — Essential, Advanced and Complete.
Project phases
Phase 1
Gap assessment audit
We review network architecture, the main information systems and their vulnerabilities, physical and environmental security, human resources security and operations security. It includes a high-level vulnerability analysis and a maturity assessment of the 93 Annex A controls.
Phase 2
Plan design and implementation
We design and implement the complete system: master schedule of recurring tasks, policies, security organisation and committee, risk management, access control, cryptography, physical security, operations, communications, development, suppliers, incidents and continuity. The order and depth follow from the Phase 1 findings.
Phase 3
Building competence and transferring knowledge
We train the team in good practice and in the requirements of the standard so the organisation can own and sustain the plan. Workshops, coaching and hands-on practice in incident management, system hardening and risk management.
Phase 4
Audits and certification
Internal audits by expert auditors independent of the advisory team, support in handling findings, and accompaniment through the certification audit. If the organisation decides to train its own internal auditors, we deliver that training.
What the implementation includes
Master schedule of recurring tasks
Information security policies
Security organisation and committee
Risk management and treatment plan
Human resources security
Asset management and classification
Access control and user management
Cryptographic controls
Physical and environmental security
Operations security
Communications security
System development and acquisition
Supplier relationships
Security incident management
Business continuity (BIA, BCP, DRP)
Technical vulnerability analysis
Frequently asked questions
How long does the project take up to certification?
A typical project runs 8 to 14 months. The implementation baseline is estimated at 12 months and is adjusted according to the agreed scope and the findings of the gap assessment audit.
What methodology do you use to measure the starting point?
Our own methodology, based on a maturity assessment of the 93 Annex A controls of ISO/IEC 27001:2022. Through interviews, document review and the gap assessment audit we determine how far each control is implemented on a six-level scale, which lets us plot the best plan by priority and effort.
Who carries out the internal audit?
Expert auditors independent of the advisory team. That separation is an impartiality requirement of the standard and stops whoever implemented the system from auditing their own work.
Does it integrate with management systems we already have?
Yes. The high-level structure shared by ISO standards allows the ISMS to be integrated with ISO 9001, ISO/IEC 20000-1, ISO 37301 or ISO/IEC 42001, sharing policy, risk management, internal audit and management review.