Our Approach and Methodology
SecureState approaches 27001 with a two-pronged approach. First, an ISO 27001 Readiness Assessment is performed to determine if 27001 certification is feasible for the client organization; and if so, what the timeframes and cost are likely to be for implementation. If the organization has not already identified the scope of its 27001 ISMS, SecureState will provide guidance here as well. Because 27001 is designed to be customized to align with an organization’s business goals and risk tolerance, each implementation is slightly different. For this reason, it is necessary to perform an initial assessment prior to tackling the large task of implementation.
If an organization chooses to pursue a 27001 program, SecureState will be engaged to assist in the 9 to 12 month process of ISMS implementation. Each project will slightly vary in which implementation tasks need to be performed, and where the organization most needs help. Some of the areas which SecureState can provide assistance include:
- Project Management
- 27001 Pre-Audit
- Incident Response Planning
- Business Continuity Planning
- Audit Program Development
- Policies & Procedures
- Documentation Format
- Control Implementation