Risk assessment
A structured, repeatable information-security and privacy risk assessment.
End-to-end build of your Information Security (ISO/IEC 27001) and Privacy Information (ISO/IEC 27701) Management Systems.
An ISMS is not a binder, it is a working system for managing information-security and privacy risk. We stand up the real thing: a risk assessment that reflects your business, a justified Statement of Applicability, the policy set, and the controls to back them.
Everything is built to integrate with how you already operate and to produce the evidence you need for ISO/IEC 27001 and ISO/IEC 27701 certification.
A structured, repeatable information-security and privacy risk assessment.
A justified SoA mapping the controls you apply and why.
The policy set and technical/organisational controls, implemented with your team.
Evidence, internal audit and support through the certification audit.
We run the risk assessment and agree treatment, the foundation everything else hangs from.
We build a Statement of Applicability that justifies every control you apply.
Policies and controls are implemented with your team and evidenced as you go.
Internal audit, management review and support through stage-1 and stage-2.
Tell us your goals and sector, and we'll scope the right engagement and propose concrete next steps.
Request a Consultation