Regulated Incident Management Ecosystem Versão portuguesa

Service sheet SO-03

Management System and Certification Readiness

Implementation of the information security management system and preparation for the certification audit, with documentation proportionate to the organisation.

The problem it solves

Certification is often treated as a documentation exercise. The result is a long manual nobody reads and practices that stay the same, until the first audit reveals the distance between them.

Who it is for

  • Organisations facing a contractual certification requirement;
  • Technology service providers;
  • Public entities with qualification requirements.

Deliverables

  • Scope, policy and statement of applicability;
  • A minimum sufficient set of policies and procedures;
  • Internal audit programme and management review;
  • Support through the certification audit stages.

Method

  1. 01

    Scope

    Scope and context.

  2. 02

    Build

    Controls and documentation.

  3. 03

    Operate

    Evidence and records.

  4. 04

    Audit

    Internal and certification.

Regulatory basis

  • ISO/IEC 27001:2022 and ISO/IEC 27002:2022;
  • ISO/IEC 27005, on information security risk management.

Expected results

  • A system implemented and actually used;
  • An audit prepared without surprises;
  • Proportionate, maintained documentation.

Security that is not measured is not managed

Start with a maturity assessment or ask for a proposal to structure the role.