One of the first steps towards ISO 27001 certification is conducting a compliance assessment. At this stage, we evaluate the current state of your organisation’s information security against the standard’s requirements and controls. The assessment includes:
GAP Assessment: Understanding the business and determining the gap between the standard’s requirements and the organisation’s practices to allocate resources for an effective and efficient implementation of the ISMS.
After the assessment, we begin the implementation phase, where we adjust or propose processes, policies, and controls to meet the standard. In this way, we define the following roadmap to achieve ISO 27001 compliance: