ISMS internal audit, surveillance support and maintenance
Independent internal audits, surveillance preparation and the 2013 to 2022 transition for companies that already hold ISO 27001.
We build your information security management system (ISMS) from where you are today to a passed Stage 2 audit. The scope, the deliverables and the fee are agreed before work begins, and we stay with you until the certificate is issued.
We agree the ISMS scope with you (which sites, systems and teams are in), then assess your current controls against ISO/IEC 27001:2022 and its 93 Annex A controls. You get a written gap report and a plan with dates.
We run the risk assessment with your team, decide which controls apply and why, and produce the Statement of Applicability. It is the first document the certification auditor asks for.
We write or adapt the documents you actually need, in plain language and sized to your organisation. A 60-person software company does not need a 200-page policy set.
We work alongside your IT and operations staff to put the controls in place: access control, change management, supplier security, logging, backups, incident handling and the rest. Where a tool is needed we say so. Where it is not, we say that too.
Short sessions for all staff and a longer session for the people who will run the ISMS day to day.
We perform the internal audit required by clause 9.2, help you hold the management review, and close the findings before the certification body arrives.
We help you choose an accredited certification body, prepare the evidence pack, and sit with you through Stage 1 and Stage 2.
Independent internal audits, surveillance preparation and the 2013 to 2022 transition for companies that already hold ISO 27001.
Get ready for Sri Lanka’s PDPA, whose core obligations commence on 1 January 2027, and align the work with ISO 27001 so you do it once.
Business impact analysis, continuity plans and exercises that prove the plans work. Certifiable to ISO 22301 if you need the certificate.
Forty-five minutes, no charge. We ask about your organisation, what is driving the project and what you already have in place, then send a written proposal with a fixed scope and fee.