The problem it solves
Without an initial measurement, security is discussed through impressions. Each department defends its own priority and the budget ends up where there is most insistence, not most risk.
Who it is for
- Organisations preparing for certification;
- Boards that need a baseline;
- Investors and buyers in acquisitions.
Deliverables
- Maturity report by control domain;
- Gap map prioritised by risk;
- Improvement plan at 90 and 180 days;
- Presentation to the management body.
Method
- 01
Collect
Documents and interviews.
- 02
Evaluate
Controls by domain.
- 03
Prioritise
Risk and effort.
- 04
Plan
Actions and owners.
Regulatory basis
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022;
- National Cybersecurity Reference Framework of the CNCS;
- Article 32 GDPR, on security of processing.
Expected results
- A measured, comparable baseline;
- Reasoned priorities;
- Investment directed at real risk.