Need a Free Consultation? Schedule a Call Now Get a Quote

ISO 27001 Consultancy and Certification Support

The ISO 27001 standard details the requirements for information security management systems. The standard has recently been updated to ISO 27001:2022.

ISO 27001 is a broad standard which is concerned with the management system employed by an organisation to manage its information security. It is similar to standards such as ISO 9001 in that it requires the communication of a clear organisational structure with clear roles and responsibilities for individuals. Additionally, organisations must demonstrate that documented information is controlled, that risks and opportunities are considered and that actions to address these are identified and implemented. However, unlike other standards, ISO 27001 differs in that it includes an Annex (Annex A) listing various control which need to be considered in the risk mitigation process.

In order to comply with the standard organisations must produce a range of documentation. These include information security policies and a statement of applicability to serve as evidence that the controls in Annex A have been addressed. Additionally the risk assessment process may include a consideration of IT infrastructure and systems.

Meeting the requirements of this standard

The standard requires organisations to conduct a full review of the flow of information – where it is stored, how it is accessed, and how it is disseminated. Organisations must also document the controls they employ to preserve their data, protect it from unauthorised access and accidental corruption or alteration and whether their systems are robust enough to ensure the availability of information for business continuity.

The 2022 revision restructured Annex A from 114 controls to 93 across four themes. our guide to the ISO 27001:2022 transition explains what changed and the steps involved in transitioning an existing ISMS.

How ISO 27001 certification works

We take you all the way to ISO 27001 certification, and certification is guaranteed, backed by a 100% success rate. We build the management system around the way your business already works, support you through your internal audit and management review so your team owns them, and close out anything an assessor would otherwise raise before the audit rather than after it.

The system we leave you with is integrated and meant to be used. It should not add workload or complexity to how you already run, and if it does then it has been built wrong. By the time the assessor arrives your people know the system and can answer for it, because it is theirs.

It is a fixed price, agreed before we start, with payment by milestones or monthly instalments. Consultancy clients also get our ISO and legal update service at no extra cost, so the system does not quietly go out of date once we have finished.

We help you choose the right certification body too, based on an objective review of what you actually need rather than who we happen to know: whether accreditation is required by your customers and tenders, what the full three-year cycle costs, and how quickly a body can realistically get an assessor to you. Lead times vary far more than prices do. Our guide to choosing a certification body works through all three.

Benefits of ISO 27001 Certification