Our Approach and Methodology
SecureState approaches 27001 with a two-pronged approach. First, an ISO
27001 Readiness Assessment is performed to determine if 27001 certification
is feasible for the client organization; and if so, what the timeframes and
cost are likely to be for implementation. If the organization has not
already identified the scope of its 27001 ISMS, SecureState will provide
guidance here as well. Because 27001 is designed to be customized to align
with an organization’s business goals and risk tolerance, each
implementation is slightly different. For this reason, it is necessary to
perform an initial assessment prior to tackling the large task of
implementation.
If an organization chooses to pursue a 27001 program, SecureState will be
engaged to assist in the 9 to 12 month process of ISMS implementation. Each
project will slightly vary in which implementation tasks need to be
performed, and where the organization most needs help. Some of the areas
which SecureState can provide assistance include:
- Project Management
- 27001 Pre-Audit
- Incident Response Planning
- Business Continuity Planning
- Audit Program Development
- Policies & Procedures
- Documentation Format
- Control Implementation