Information security

ISO/IEC 27001 ISMS implementation

Planning, design, knowledge transfer and support for implementing and maintaining an Information Security Management System under the ISO/IEC 27000 framework.

Typical duration
8 to 14 months
Delivery
Blended — on site and remote
Support
SORT Redmine included
Levels
Essential · Advanced · Complete

Objective and scope

We provide specialist support and coaching in information security through a highly qualified team. Engagements can start immediately, with a blended methodology: on-site visits combined with remote work. The four phases make up the core of the ISMS implementation, common to all three service levels — Essential, Advanced and Complete.


Project phases

Phase 1

Gap assessment audit

We review network architecture, the main information systems and their vulnerabilities, physical and environmental security, human resources security and operations security. It includes a high-level vulnerability analysis and a maturity assessment of the 93 Annex A controls.

Phase 2

Plan design and implementation

We design and implement the complete system: master schedule of recurring tasks, policies, security organisation and committee, risk management, access control, cryptography, physical security, operations, communications, development, suppliers, incidents and continuity. The order and depth follow from the Phase 1 findings.

Phase 3

Building competence and transferring knowledge

We train the team in good practice and in the requirements of the standard so the organisation can own and sustain the plan. Workshops, coaching and hands-on practice in incident management, system hardening and risk management.

Phase 4

Audits and certification

Internal audits by expert auditors independent of the advisory team, support in handling findings, and accompaniment through the certification audit. If the organisation decides to train its own internal auditors, we deliver that training.


What the implementation includes

  • Master schedule of recurring tasks
  • Information security policies
  • Security organisation and committee
  • Risk management and treatment plan
  • Human resources security
  • Asset management and classification
  • Access control and user management
  • Cryptographic controls
  • Physical and environmental security
  • Operations security
  • Communications security
  • System development and acquisition
  • Supplier relationships
  • Security incident management
  • Business continuity (BIA, BCP, DRP)
  • Technical vulnerability analysis

Frequently asked questions

How long does the project take up to certification?

A typical project runs 8 to 14 months. The implementation baseline is estimated at 12 months and is adjusted according to the agreed scope and the findings of the gap assessment audit.

What methodology do you use to measure the starting point?

Our own methodology, based on a maturity assessment of the 93 Annex A controls of ISO/IEC 27001:2022. Through interviews, document review and the gap assessment audit we determine how far each control is implemented on a six-level scale, which lets us plot the best plan by priority and effort.

Who carries out the internal audit?

Expert auditors independent of the advisory team. That separation is an impartiality requirement of the standard and stops whoever implemented the system from auditing their own work.

Does it integrate with management systems we already have?

Yes. The high-level structure shared by ISO standards allows the ISMS to be integrated with ISO 9001, ISO/IEC 20000-1, ISO 37301 or ISO/IEC 42001, sharing policy, risk management, internal audit and management review.

your business partner

Protecting you today, innovating for tomorrow