GRC / GRC-03
ISO/IEC 27001 and ISMS implementation support
Establishing an information security management system: responsibilities, risks, controls, evidence and continual improvement, with optional certification preparation.

WHEN IT HELPS
A focused response
to a defined need.
Executives or CISO; customer requirements, governance improvements or certification plans for a defined scope.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Gap analysis
- ISMS scope
- risk treatment, policies, operating evidence and review preparation
Deliverables
- ISMS roadmap
- tailored documentation
- evidence pack and certification-audit preparation
Acceptance evidence
Processes are more than documents: owners, records and reviews can be demonstrated within the agreed scope.
DELIVERY
How the work is structured.
Approach
Scope context; engage business owners and decision-makers; assess risks or gaps; decide controls; organise follow-up and evidence.
Prerequisites & responsibilities
Customer: sponsor, available business owners, risk decisions and legal advice where needed. Provider: methodology, facilitation, analysis and decision file.
Scope factors
Entities, processes, stakeholders, regulatory scope, document maturity and workshops. Project, periodic support or fractional CISO depending on need.
Questions to clarify
Why pursue certification? What is the exact scope? Who will operate the ISMS afterwards?
IMPORTANT BOUNDARIES
Implementation support is not a certification audit; distinguish internal audit, consulting and certification-body independence.
The work supports decisions and evidence for the agreed framework. Legal advice, independent certification and the decisions of regulators or assessors remain separate responsibilities.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A B2B SaaS company faces a customer certification requirement. Project: define scope and put the ISMS into operation. Target outcome: coherent evidence for external assessment; certification remains the certification body’s decision.
Scenario 02
A group has policies but no evidence of access reviews. Project: turn the procedure into a recurring activity. Target outcome: named owners, completed campaigns and retained results; documentation alone does not close the gap.
Technology and reference context
ISO/IEC 27001, document management or GRC tooling selected for context; licensed standard where required.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
