Français: această pagină nu e încă tradusă. Textul de mai jos e în English.
The mistake that costs at ISO 27001 is treating it as a project with an end: gather documents, get the certificate, done. The standard is a management system (ISMS) you need to operate continuously and demonstrate — at certification, but also at the annual surveillance audits and the three-year recertification. Our role is to build it solidly and keep it defensible, not just to get you through once.
What it involves, concretely
The standard has two parts evaluated differently: the management clauses (4–10) — context, leadership, planning, operation, evaluation, improvement — and the controls in Annex A, in the 2022 version 93 controls across four themes (organisational, people, physical, technological). Controls are not applied wholesale; they are selected based on risk, and the selection is justified in the Statement of Applicability. A good auditor starts exactly there: why you included or excluded each control.
How we work
- Gap analysis against clauses 4–10 and Annex A
- ISMS construction: risk assessment and treatment, objectives, policies, roles
- Statement of Applicability (SoA) — justified, not copied from a template
- Preparation for Stage 1 (documentation and design review) and Stage 2 (implementation and operating effectiveness — walkthroughs of Annex A controls)
- Internal audit and surveillance preparation
We are clear: we prepare, verify and conduct internal audits — but the certification decision belongs to an accredited body. We bring you to the point where you pass without surprises.
What you get
Gap analysis report, risk assessment and treatment plan, Statement of Applicability, internal audit report and a prioritised remediation roadmap.