Skip to content

Home Expertise / Risk & governance

GRC / GRC-03

ISO/IEC 27001 and ISMS implementation support

Establishing an information security management system: responsibilities, risks, controls, evidence and continual improvement, with optional certification preparation.

WHEN IT HELPS

A focused response
to a defined need.

Executives or CISO; customer requirements, governance improvements or certification plans for a defined scope.

AT A GLANCE

Family
Risk & governance

Engagement
Advisory

Reference
GRC-03

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Gap analysis
  • ISMS scope
  • risk treatment, policies, operating evidence and review preparation

Deliverables

  • ISMS roadmap
  • tailored documentation
  • evidence pack and certification-audit preparation

Acceptance evidence

Processes are more than documents: owners, records and reviews can be demonstrated within the agreed scope.

DELIVERY

How the work is structured.

Approach

Scope context; engage business owners and decision-makers; assess risks or gaps; decide controls; organise follow-up and evidence.

Prerequisites & responsibilities

Customer: sponsor, available business owners, risk decisions and legal advice where needed. Provider: methodology, facilitation, analysis and decision file.

Scope factors

Entities, processes, stakeholders, regulatory scope, document maturity and workshops. Project, periodic support or fractional CISO depending on need.

Questions to clarify

Why pursue certification? What is the exact scope? Who will operate the ISMS afterwards?

IMPORTANT BOUNDARIES

Implementation support is not a certification audit; distinguish internal audit, consulting and certification-body independence.

The work supports decisions and evidence for the agreed framework. Legal advice, independent certification and the decisions of regulators or assessors remain separate responsibilities.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A B2B SaaS company faces a customer certification requirement. Project: define scope and put the ISMS into operation. Target outcome: coherent evidence for external assessment; certification remains the certification body’s decision.

Scenario 02

A group has policies but no evidence of access reviews. Project: turn the procedure into a recurring activity. Target outcome: named owners, completed campaigns and retained results; documentation alone does not close the gap.

Technology and reference context

ISO/IEC 27001, document management or GRC tooling selected for context; licensed standard where required.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.