We tailor every compliance review to our clients’ requirements; however we have a four phase fundamental process that normally meets our clients’ needs and creates an efficient unobtrusive review so you can focus on your business and we can focus on your compliance.
Scope (phase 1): Since the International Organization for Standardization (ISO) 27001 outlines specific requirements, defining the scope of an ISO 27001 engagement involves understand how your organization’s information security requirements and security objectives aligns with the ISO 27001 standards. Do not be concerned if you have not defined your information security requirements or objectives; we work closely with your management to help define this process and ensure we have an accurate scope for the engagement.
Plan (phase 2): We offer two options for the planning phase of your review.
Fieldwork (phase 3): Consists of onsite interviews, walkthrough of relevant business processes and testing as it relates to ISO 27001. Our auditors have a minimum of five years of experience with the big 4, large consulting firms and smaller boutique firms specializing in information technology advisory services. Due to this we are efficient and understand what is required for each review. Don’t worry, you don’t have to train our auditors, we are qualified at what we sell.
Report (phase 4): Your ISO 27001 report and recommendations is essentially what you pay us for, therefore we make sure that we have well-written, well-defined deliverables that are focused on providing your organization with everything needed to understand how you compare to ISO 27001 standards. We also provide management recommendations and a road map to correct any deficiencies identified. We take pride in delivering quality and timely reports and stand behind everything we issue.