ISO 27001 Readiness

InfoGuard ISO Kit

A structured readiness engagement that prepares the organisation to pursue ISO 27001:2022 certification. Scope, timeline, policy set, risk work, and audit-preparation support are confirmed after discovery. Certification remains the decision of an independent accredited certification body.

Commercial model

Scoped

Timeline confirmed after discovery

Review Engagement

Phase 1

Assessment & Foundation

Gap analysis, scope definition, ISMS framework design

Phase 2

Documentation & Training

Policy suite development, risk assessment, staff training

Phase 3

Audit Preparation

Internal audit, evidence gathering, and certification-readiness preparation

What's Included

ISO 27001:2022 Gap Analysis

Assessment against all 93 Annex A controls with RAG-rated findings and prioritised remediation

ISMS Policy Suite

Information security policies and procedures developed for the organisation's agreed ISMS scope

Risk Assessment Framework

ISO 27005-aligned risk methodology with initial risk register and treatment plan

Statement of Applicability

Completed SoA with justification for all Annex A control inclusions and exclusions

Staff Awareness Training

ISO 27001 awareness training session for the agreed audience covering responsibilities under the ISMS

Internal Audit Support

Guidance through the internal audit process with evidence collection templates

Certification Body Preparation

Stage 1 and Stage 2 audit preparation including document review and mock audit

Management Review Facilitation

Facilitation of the mandatory ISO 27001 management review meeting

Deliverables

  • Gap analysis report with RAG-rated findings
  • Editable ISMS policy suite defined by the agreed scope
  • Risk register and risk treatment plan
  • Statement of Applicability (SoA)
  • Asset register template
  • Supplier security assessment questionnaire
  • Certification audit evidence pack
  • Management review presentation

Why ISO 27001:2022?

ISO 27001 provides a governed framework for an information security management system. Whether certification is required, commercially valuable, or appropriate depends on the organisation's contractual, regulatory, risk, and assurance context.

Ready to structure your ISO 27001 certification programme?