Security Program and Certification Readiness
ISO 27001 and ISO 27701 Implementation and Certification Readiness
ISMS and PIMS implementation carried through certification: scope, risk assessment, statement of applicability, internal audit, and stage one and two support.
Overview
Design and implementation of an information security management system and, where privacy obligations warrant it, an extension to a privacy information management system. Includes scope definition, statement of applicability, risk assessment methodology, mandatory documentation, internal audit, and management review, carried through to the certification body's stage one and stage two audits.
Who it is for
Designed for growth-stage and venture-backed companies building the security program enterprise customers require, and established organizations measuring and maturing an existing security program.
What you receive
ISMS documentation set, risk assessment, statement of applicability, internal audit report, management review record.
How engagements work
Every engagement is scoped individually and conducted under a master services agreement and mutual confidentiality terms. Work begins with a scoping conversation to understand your objectives, constraints, and deadlines, followed by a written statement of work defining scope, deliverables, and timeline. Both parties retain the right to decline an engagement where the fit is not right.