Information security management

ISO 27001 Implementation & Readiness

Practical ISMS design, risk treatment, control mapping and audit-readiness support grounded in your real operating environment.

ISO/IEC 27001:2022ISO/IEC 27002:2022ISO/IEC 27005:2022

Scope of support

What the engagement can cover.

Scope is tailored to the certification basis, current lifecycle state and evidence already available.

  1. 01

    ISMS scope and context definition

  2. 02

    Asset and risk assessment method

  3. 03

    Statement of Applicability

  4. 04

    Policy and control implementation

  5. 05

    Internal audit support

  6. 06

    Management review and certification readiness

Typical outputs

ISMS roadmapRisk registerSoA reviewAudit readiness pack

Training & working sessions

From standard text
to project decisions.

Modules combine standards context with the documents, reviews and evidence choices teams make during delivery.

Phase 01

Scope & gap analysis

Define boundaries, interested parties and current-state gaps.

Phase 02

Risk treatment

Assess risks and select proportionate controls.

Phase 03

Operate the ISMS

Evidence, metrics, incident learning and continual improvement.

Phase 04

Audit readiness

Internal audit, management review and corrective action.

Instructor assignments and any claimed program history are provided only after internal approval and verification.

Engagement scoping

Information that makes the first review useful.

No compliance outcome is promised from a website form. Scope begins with the program facts and evidence that can actually be reviewed.

01

Applicable basis

Standard revision, authority or customer basis, assurance level and agreed means of compliance.

02

Lifecycle state

Current milestone, approved plans, baselines, open findings and target review date.

03

Requested boundary

Training, gap analysis, document review, evidence recovery or audit-readiness support.

FAQ

Questions before the first workshop.

Does ISO 27001 certify a product?+

No. ISO/IEC 27001 certifies an information security management system within a defined organizational scope.

Can ISO 27001 support NIS2 readiness?+

Yes. A functioning ISMS can provide reusable governance, risk, incident and control evidence, while NIS2-specific legal obligations still require separate mapping.

Start with a technical conversation

Make your ISO 27001 evidence easier to defend.

Tell us the standard, lifecycle stage and evidence challenge. We will help frame a focused next step.

info@heraklet.com ↗

We use your details only to respond to this request.