Scope & gap analysis
Define boundaries, interested parties and current-state gaps.
Information security management
Practical ISMS design, risk treatment, control mapping and audit-readiness support grounded in your real operating environment.
Scope of support
Scope is tailored to the certification basis, current lifecycle state and evidence already available.
ISMS scope and context definition
Asset and risk assessment method
Statement of Applicability
Policy and control implementation
Internal audit support
Management review and certification readiness
Typical outputs
Training & working sessions
Modules combine standards context with the documents, reviews and evidence choices teams make during delivery.
Define boundaries, interested parties and current-state gaps.
Assess risks and select proportionate controls.
Evidence, metrics, incident learning and continual improvement.
Internal audit, management review and corrective action.
Instructor assignments and any claimed program history are provided only after internal approval and verification.
Engagement scoping
No compliance outcome is promised from a website form. Scope begins with the program facts and evidence that can actually be reviewed.
Standard revision, authority or customer basis, assurance level and agreed means of compliance.
Current milestone, approved plans, baselines, open findings and target review date.
Training, gap analysis, document review, evidence recovery or audit-readiness support.
FAQ
No. ISO/IEC 27001 certifies an information security management system within a defined organizational scope.
Yes. A functioning ISMS can provide reusable governance, risk, incident and control evidence, while NIS2-specific legal obligations still require separate mapping.
Start with a technical conversation
Tell us the standard, lifecycle stage and evidence challenge. We will help frame a focused next step.
info@heraklet.com ↗