InfoGuard ISO Kit
A structured readiness engagement that prepares the organisation to pursue ISO 27001:2022 certification. Scope, timeline, policy set, risk work, and audit-preparation support are confirmed after discovery. Certification remains the decision of an independent accredited certification body.
Phase 1
Assessment & Foundation
Gap analysis, scope definition, ISMS framework design
Phase 2
Documentation & Training
Policy suite development, risk assessment, staff training
Phase 3
Audit Preparation
Internal audit, evidence gathering, and certification-readiness preparation
What's Included
ISO 27001:2022 Gap Analysis
Assessment against all 93 Annex A controls with RAG-rated findings and prioritised remediation
ISMS Policy Suite
Information security policies and procedures developed for the organisation's agreed ISMS scope
Risk Assessment Framework
ISO 27005-aligned risk methodology with initial risk register and treatment plan
Statement of Applicability
Completed SoA with justification for all Annex A control inclusions and exclusions
Staff Awareness Training
ISO 27001 awareness training session for the agreed audience covering responsibilities under the ISMS
Internal Audit Support
Guidance through the internal audit process with evidence collection templates
Certification Body Preparation
Stage 1 and Stage 2 audit preparation including document review and mock audit
Management Review Facilitation
Facilitation of the mandatory ISO 27001 management review meeting
Deliverables
- ✓Gap analysis report with RAG-rated findings
- ✓Editable ISMS policy suite defined by the agreed scope
- ✓Risk register and risk treatment plan
- ✓Statement of Applicability (SoA)
- ✓Asset register template
- ✓Supplier security assessment questionnaire
- ✓Certification audit evidence pack
- ✓Management review presentation
Why ISO 27001:2022?
ISO 27001 provides a governed framework for an information security management system. Whether certification is required, commercially valuable, or appropriate depends on the organisation's contractual, regulatory, risk, and assurance context.


