Skip to content

01 — ISO management systems

ISO/IEC 27001

We implement your Information Security Management System (ISMS) and support you through the certification audit conducted by an accredited body.

Request an assessmentISO/IEC 27001:2022

What is it?

What is it?

ISO/IEC 27001 is the international standard that sets the requirements for an Information Security Management System (ISMS). It preserves the confidentiality, integrity and availability of information through a risk-based approach.

The 2022 edition reorganizes the Annex A controls into four themes —organizational, people, physical and technological— and adds topics such as threat intelligence, cloud service security and configuration management.

The certificate is issued by an accredited certification body. Delour designs and implements the system, performs the internal audit and supports you throughout the certification process.

Benefits

Benefits

  • 01

    Lower risk of information leakage, loss or tampering.

  • 02

    Verifiable evidence of control for clients, partners and auditors.

  • 03

    Access to tenders and contracts that require certification.

  • 04

    A structured response to security incidents.

  • 05

    Support for data protection compliance obligations.

  • 06

    Integration with other management systems such as ISO 9001.

How we do it

How we do it

  1. 01

    Gap analysis

    We assess your current state against the standard's requirements and the Annex A controls.

  2. 02

    Scope and context

    We define the ISMS scope, interested parties and critical information assets.

  3. 03

    Risk assessment and treatment

    We apply a risk methodology and prepare the Statement of Applicability.

  4. 04

    Control implementation

    We document policies and procedures and coordinate technical controls with your IT team.

  5. 05

    Internal audit and management review

    We verify the system's effectiveness and prepare leadership for its formal review.

  6. 06

    Certification support

    We assist you during the certification body's stage 1 and stage 2 audits and in closing findings.

Deliverables

  • Gap analysis report.
  • Risk methodology and risk register.
  • Statement of Applicability (SoA).
  • ISMS policies and procedures.
  • Risk treatment plan.
  • Internal audit report.
  • Training and awareness program.

Estimated duration

4 to 9 months, depending on scope and initial maturity.

Indicative reference; the final timeline is set during the assessment.

Frequently asked questions

Frequently asked questions

Request a ISO/IEC 27001 assessment

A specialist will review your case and propose a work plan with scope, timeline and deliverables.

Request an assessment