ISO/IEC 27001 preparation

Build an ISMS that manages risk before preparing for certification.

IKNSA assesses the organisation's ability to define its scope, treat the risks, operate the controls and demonstrate the improvement expected of a management system.

Evidence chainObserve · qualify · prioritise
  1. Scope
  2. Findings
  3. Risks
  4. Trajectory

The decision point

Certification becomes sustainable when the management system produces decisions and evidence in the course of operations.

The readiness audit starts from the context, the interested parties and the scope, then examines risk assessment, treatment, responsibilities and the life of the controls. It verifies the consistency between documents, observed practices, results and improvement.

TriggerA certification project, a scope extension or an ISMS to relaunch
ScopeScope, management, risks, controls and evidence
Expected outputReadiness gaps and an upgrade programme

Working scope

The dimensions examined together.

The framing avoids treating separately subjects that condition one another. The final scope remains adapted to the organisation and its priorities.

  1. Context, interested parties and scope
  2. Leadership, roles and policy
  3. Risk assessment and treatment
  4. Selected controls and statement of applicability
  5. Measurement, internal audit and management review
  6. Non-conformities and continuous improvement

A usable result

A preparation trajectory that strengthens risk management.

Gaps are connected to the requirements, the risks and the expected evidence. The programme distinguishes the ISMS foundations, putting the controls into operation and preparing for the certification audit.

  1. 01Scope and readiness assessment
  2. 02Gaps by requirement and level of evidence
  3. 03Treatment plan and responsibilities
  4. 04Internal audit programme and management review

Method

An engagement that stays readable from scope to decision.

01

Scope

Fix the entities, services, assets, periods and frameworks actually examined.

02

Observe

Cross-check interviews, documents, configurations and operational results without relying on declarations alone.

03

Prioritise

Connect each finding to its business impact, its likelihood and the controls already in place.

04

Decide

Produce a costed trajectory with owners, deadlines, dependencies and expected evidence.

Point of vigilance

What the engagement must make explicit.

The existence of policies does not demonstrate that the controls work. The evidence must be representative of the scope, dated and produced by a management cycle alive enough to be assessed.

The first conversation verifies the context, the level of urgency, the stakeholders and the output genuinely expected.

Frame this engagement See Audit & compliance Start with a guided assessment

First conversation

Let’s discuss the next point of control for your information system.

A project to frame, operations to take over, compliance to demonstrate? Describe the context. You will get a first considered reading — not a generic brochure.