Phase 1
Planning and interviews
We define the scope, identify the counterparts and interview the business, IT and support teams to understand processes, assets and dependencies.
Information security
To improve information security management you first have to know your starting point. The assessment establishes the real gaps and turns a hunch about risk into a plan with priorities, effort and owners.
We determine how far each of the 93 Annex A controls of ISO/IEC 27001:2022 is implemented, through personal interviews, document review and technical verification. Our six-level maturity scale gives an objective reading of compliance and a holistic view by control domain, from which the optimal plan in terms of priority and effort follows.
Phase 1
We define the scope, identify the counterparts and interview the business, IT and support teams to understand processes, assets and dependencies.
Phase 2
We review existing policies, procedures and records, and run a high-level vulnerability analysis over exposed infrastructure and systems.
Phase 3
We assess the 93 controls independently against the six-level scale, giving the current state control by control and domain by domain.
Phase 4
We present the Board with the gaps, the level of risk being carried, the immediate actions and a plan prioritised by criticality and effort, with an estimate of the resources required.
Yes, and that is the most common case. The assessment uses ISO/IEC 27001 as its frame of reference because it is complete and widely recognised, but the deliverable is a security roadmap that is useful regardless of any decision to certify.
No. It includes a high-level vulnerability analysis over infrastructure and systems, which is broader and shallower than a pentest. If you need a focused penetration test, we handle that as a separate engagement.
Annually, or whenever something significant changes: a merger, a change of critical IT supplier, a new line of business or a serious incident.
your business partner