ISO/IEC 27001 preparation
Build an ISMS that manages risk before preparing for certification.
IKNSA assesses the organisation's ability to define its scope, treat the risks, operate the controls and demonstrate the improvement expected of a management system.
- Scope
- Findings
- Risks
- Trajectory
The decision point
Certification becomes sustainable when the management system produces decisions and evidence in the course of operations.
The readiness audit starts from the context, the interested parties and the scope, then examines risk assessment, treatment, responsibilities and the life of the controls. It verifies the consistency between documents, observed practices, results and improvement.
Working scope
The dimensions examined together.
The framing avoids treating separately subjects that condition one another. The final scope remains adapted to the organisation and its priorities.
- Context, interested parties and scope
- Leadership, roles and policy
- Risk assessment and treatment
- Selected controls and statement of applicability
- Measurement, internal audit and management review
- Non-conformities and continuous improvement
A usable result
A preparation trajectory that strengthens risk management.
Gaps are connected to the requirements, the risks and the expected evidence. The programme distinguishes the ISMS foundations, putting the controls into operation and preparing for the certification audit.
- 01Scope and readiness assessment
- 02Gaps by requirement and level of evidence
- 03Treatment plan and responsibilities
- 04Internal audit programme and management review
Method
An engagement that stays readable from scope to decision.
Scope
Fix the entities, services, assets, periods and frameworks actually examined.
Observe
Cross-check interviews, documents, configurations and operational results without relying on declarations alone.
Prioritise
Connect each finding to its business impact, its likelihood and the controls already in place.
Decide
Produce a costed trajectory with owners, deadlines, dependencies and expected evidence.
Point of vigilance
What the engagement must make explicit.
The existence of policies does not demonstrate that the controls work. The evidence must be representative of the scope, dated and produced by a management cycle alive enough to be assessed.
The first conversation verifies the context, the level of urgency, the stakeholders and the output genuinely expected.
Frame this engagement See Audit & compliance Start with a guided assessmentFirst conversation
Let’s discuss the next point of control for your information system.
A project to frame, operations to take over, compliance to demonstrate? Describe the context. You will get a first considered reading — not a generic brochure.