01 — ISO management systems
ISO/IEC 27001
We implement your Information Security Management System (ISMS) and support you through the certification audit conducted by an accredited body.
What is it?
What is it?
ISO/IEC 27001 is the international standard that sets the requirements for an Information Security Management System (ISMS). It preserves the confidentiality, integrity and availability of information through a risk-based approach.
The 2022 edition reorganizes the Annex A controls into four themes —organizational, people, physical and technological— and adds topics such as threat intelligence, cloud service security and configuration management.
The certificate is issued by an accredited certification body. Delour designs and implements the system, performs the internal audit and supports you throughout the certification process.
Benefits
Benefits
- 01
Lower risk of information leakage, loss or tampering.
- 02
Verifiable evidence of control for clients, partners and auditors.
- 03
Access to tenders and contracts that require certification.
- 04
A structured response to security incidents.
- 05
Support for data protection compliance obligations.
- 06
Integration with other management systems such as ISO 9001.
How we do it
How we do it
- 01
Gap analysis
We assess your current state against the standard's requirements and the Annex A controls.
- 02
Scope and context
We define the ISMS scope, interested parties and critical information assets.
- 03
Risk assessment and treatment
We apply a risk methodology and prepare the Statement of Applicability.
- 04
Control implementation
We document policies and procedures and coordinate technical controls with your IT team.
- 05
Internal audit and management review
We verify the system's effectiveness and prepare leadership for its formal review.
- 06
Certification support
We assist you during the certification body's stage 1 and stage 2 audits and in closing findings.
Deliverables
- Gap analysis report.
- Risk methodology and risk register.
- Statement of Applicability (SoA).
- ISMS policies and procedures.
- Risk treatment plan.
- Internal audit report.
- Training and awareness program.
Estimated duration
4 to 9 months, depending on scope and initial maturity.
Indicative reference; the final timeline is set during the assessment.
Frequently asked questions
Frequently asked questions
Request a ISO/IEC 27001 assessment
A specialist will review your case and propose a work plan with scope, timeline and deliverables.
Request an assessment