LST ISO/IEC 27001:2022/Amd 1:2024 specifies the requirements for an information security management system to enable an organisation to assess risks and put in place appropriate controls to protect the confidentiality, integrity, and availability of information through a risk management process.
Organisations that apply this standard can obtain ISO/IEC 27001 certification if they are audited by an accredited certification body. The certificate demonstrates that the company follows best practices in information security as well as provides a competitive advantage.
We implement an information security management system based on the ISO 27001 security standard and develop the necessary policies, procedures, and other documents
We develop Information Security Management System (ISMS) roles, functions, and responsibilities.
Inventory digital assets and their owners.
We carry out a risk assessment and provide the results and an action plan. We also prepare a risk assessment methodology.
We prepare a methodology for the IT internal audit process.
We assess your organisation’s information security controls against ISO 27002.