How we work
01Gap analysis
Current state against the requirements of the standard and the 93 Annex A controls.
02Scope and context
Defining the ISMS scope, interested parties and their requirements.
03Risk assessment
Methodology, risk register, treatment plan and risk acceptance criteria.
04Statement of Applicability
Justification for each control included or excluded.
05Documentation and implementation
Policies, procedures and records, with staff training.
06Internal audit and certification
Internal audit programme, management review and support through the certification audit.
What you get
ISMS documentation
Risk register
Statement of Applicability
Internal audit report
Management review
Certification readiness
Measures of Annex II this service covers
01 Commitment and accountability of those responsible for implementing cyber risk management measures
02 Management of software and hardware assets
03 Risk management
04 Security of human resources and digital identities
07 Physical and logical access control to network and information systems
08 Supply chain security
12 Business continuity and cyber crisis management
Sectors where it is most in demand
Check for yourself before we talk
Entity categorisation check
Readiness check against the 13 measures
Incident reporting deadline calculator
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.