ISMS / 05

Build the system.
Prepare for certification.

We help organisations establish, test and improve an information security management system aligned to ISO/IEC 27001:2022 before independent certification audit.

READINESS LEDGER

ISO/IEC 27001:2022 Readiness

01
Scope
02
Requirement
03
Evidence
04
Remediation
WHAT YOU GET

Readiness expressed through evidence.

Outputs are tied to the defined scope and do not imply certification, attestation or a legal conclusion.

01

ISMS completeness

Connect context, leadership, risk, objectives, operation and improvement.

02

Risk-control traceability

Link information-security risks to treatment and the Statement of Applicability.

03

Audit readiness

Test documented information, internal audit and management review evidence.

EXPERTISE & APPROACH

A controlled path from requirement to readiness.

01 / Context

Define scope, interested parties, processes and information-security objectives.

02 / Design

Build the risk method, treatment, controls, roles and documented system.

03 / Operate

Generate evidence through implementation, measurement and issue handling.

04 / Assure

Conduct readiness review and support internal audit and management review preparation.

GOOD FIT

Use this service when

  • Customers or strategy require an independently certified ISMS.
  • Security controls exist but lack one management system.
  • The organisation is transitioning from ISO/IEC 27001:2013.
LIMITS & BOUNDARIES

Plan for these realities

  • Certification can only be issued by an independent certification body.
  • Readiness work should preserve independence for any formal internal audit role.
  • Conformity requires operating evidence, not documents alone.
ILLUSTRATIVE ENGAGEMENT

An ISO/IEC 27001:2022 ISMS readiness programme.

Scope and gap review · ISMS design · operating evidence · certification readiness

EVIDENCE FRAMEWORK

Evidence before assurance.

A ISO 27001 Readiness engagement should leave a useful evidence trail: an agreed baseline, documented decisions, delivered artefacts and an outcome review against the measures defined at the start.

Which part of the ISMS is not yet operating as a system?

Bring the target framework, expected review date and current evidence. We’ll help define the right readiness scope.

Companions Corp d.o.o.

Srebrenička bb · Bosanski Petrovac · office@companionscorp.com

top