The problem it solves
Certification is often treated as a documentation exercise. The result is a long manual nobody reads and practices that stay the same, until the first audit reveals the distance between them.
Who it is for
- Organisations facing a contractual certification requirement;
- Technology service providers;
- Public entities with qualification requirements.
Deliverables
- Scope, policy and statement of applicability;
- A minimum sufficient set of policies and procedures;
- Internal audit programme and management review;
- Support through the certification audit stages.
Method
- 01
Scope
Scope and context.
- 02
Build
Controls and documentation.
- 03
Operate
Evidence and records.
- 04
Audit
Internal and certification.
Regulatory basis
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022;
- ISO/IEC 27005, on information security risk management.
Expected results
- A system implemented and actually used;
- An audit prepared without surprises;
- Proportionate, maintained documentation.