ISMS Implementation & ISO/IEC 27001 Rollout | ISMS Matters
351
page-template,page-template-full_width,page-template-full_width-php,page,page-id-351,page-child,parent-pageid-120,ajax_fade,page_not_loaded,,footer_responsive_adv,hide_top_bar_on_mobile_header,qode-content-sidebar-responsive,qode-theme-ver-10.1.1,wpb-js-composer js-comp-ver-5.0.1,vc_responsive
 

ISMS Implementation

End to End Assistance

ISO/IEC 27001 Implementation and Rollout

As well as using the ISO/IEC 27001 Standard for Information Security Management Systems (ISMS) as a baseline for carrying out information assurance assessments, we can also provide consultancy around implementation of an ISMS within an organisation.

 

We can provide end-to-end assistance at every stage of ISMS development and implementation.

ISMS implementation

Specific areas of knowledge

Although each business – and therefore implementation – is different, this service could involve helping with:

 

  •  ISMS scoping, setup and design
  • Asset identification
  • Risk assessments
  • Preparation of risk treatment plans
  • Production of a Statement of Applicability (SoA) and other documentation for certification
  • Awareness training
  • Performance and Measurement

 

Or, we can deliver various aspects of the above (or of the ISO 2700 family of standards), typically through the use of workshops for skills transfer.

Inception to certification

It is important to note that we can take a business or organisation all the way from inception to the point of certification, at that point a UKAS accredited (registered) certification body (e.g. BSI, CI, KPMG) will then carry out a Stage 1 certification audit.

 

Our consultants have taken over forty clients through to certification with no major non conformities.

 

We hold certifications for ISO/IEC 27001 and our consultants have passed the following courses:

 

  • ISO/IEC 27001 Lead Auditor; ISO audit competencies (BSI);
  • ISO/IEC 27001 Lead Implementer; ISO implementation competencies (BSI);
  • XISEC Risk Management
  • Internal Audit

A full service

The Standard is completely risk-based and requires that detailed risk assessments are carried out, using a documented risk methodology that aligns with ISO/IEC 27005 and ISO/IEC 31000.

 

If the client does not have their own risk assessment methodology, we can provide them with our own as a start point and can take them through the risk assessment process using workshops if required.

Please contact us now for a free quote on your upcoming requirements or project…