ISMS DESIGN & CERTIFICATION READINESS

ISO 27001 Consulting

Build an information security management system that governs risk, produces evidence, and is ready for independent certification review.

Technical colleagues reviewing work together

HOW THE WORK MOVES

Make the ISMS match the organization—not a folder of borrowed documents.

  1. 01

    Define ISMS scope

    Confirm organizational, technology, location, interface, and interested-party boundaries.

  2. 02

    Assess risk

    Establish a usable method, inventory risk, and document treatment decisions.

  3. 03

    Design the ISMS

    Build governance, Statement of Applicability, policies, controls, roles, and evidence routines.

  4. 04

    Operate and review

    Run controls, internal audit, management review, corrective action, and improvement cycles.

  5. 05

    Prepare certification

    Close blockers and coordinate evidence for Stage 1 and Stage 2 with the selected certification body.

TIMELINE

Sequenced around the actual starting point.

Certification timing depends on scope, current maturity, risk work, the period needed to operate the ISMS, and certification-body availability. The schedule is confirmed after scoping.

DELIVERABLES

Enough detail to act and defend the plan.

  • ISMS scope and governance model
  • Risk methodology, register, and treatment plan
  • Statement of Applicability
  • Policy and control set
  • Evidence calendar and corrective-action log
  • Internal-audit and management-review preparation

COMMON FAILURE MODES

Where readiness work loses time.

Oversized scope

An unclear or unnecessarily broad boundary creates control and evidence obligations the team cannot sustain.

Static risk register

Risk work must drive treatment and review decisions, not exist only for certification.

Control copying

Annex A controls must be selected and implemented through risk treatment and the organization’s actual operating model.

Late internal audit

Waiting until the end leaves little time to address systemic findings before certification review.

FREQUENT QUESTIONS

What teams usually need to know.

Does Awaken Arrow issue ISO 27001 certification?

No. Certification is issued by an accredited independent certification body. We design and prepare the ISMS.

Is the Statement of Applicability just an Annex A checklist?

No. It records which controls are necessary, why they are included or excluded, and implementation status based on the organization’s risks and obligations.

Can ISO 27001 and SOC 2 share controls?

Often, yes. A common control and evidence system can reduce duplicate work while preserving framework-specific requirements.

Do you support internal audit preparation?

Yes. We help plan internal audit coverage, organize evidence, track corrective action, and prepare management review inputs.

Can the ISMS cover cloud services and remote work?

Yes. Scope should reflect the people, processes, technology, locations, and interfaces involved in the services being protected.

A USEFUL FIRST CONVERSATION

Build an ISMS your team can keep operating.

Tell us your target, current stage, and decision date. We will outline the information needed to scope a useful first phase.