ISO 27001 Gap Assessment
Current-state assessment against the agreed ISO/IEC 27001 scope, with evidence review, prioritised gaps and remediation roadmap.
Choose a bounded assessment, a readiness project, or an ongoing managed GRC programme. The service design separates advisory work from independent assurance where required.
The primary service line for organisations that need to understand, build, test and maintain information-security controls.
Current-state assessment against the agreed ISO/IEC 27001 scope, with evidence review, prioritised gaps and remediation roadmap.
ISMS scope, risk methodology, risk treatment, Statement of Applicability support, policies, control ownership and evidence readiness.
Audit planning, sampling, interviews, evidence review, findings and corrective-action tracking where independence and competence requirements are satisfied.
Risk-register maintenance, evidence calendar, policy reviews, access/vendor oversight, corrective actions, management review support and surveillance readiness.
Risk identification and treatment focused on business processes, information assets, cloud services, suppliers and technical exposure.
Structured due diligence, evidence review, risk classification, exceptions and remediation tracking for critical suppliers.
Use technical inspection to determine whether a documented control is actually operating.
Entra roles, MFA, Conditional Access, privileged access, account lifecycle, SharePoint, Intune, BitLocker, Defender and audit evidence.
Encryption, patching, endpoint protection, local privilege, firewall, inventory and security configuration evidence.
Identity, logging, privileged access, backups, network exposure, change control and evidence across Azure, AWS, Linux and network environments.
Automation is used when it makes a control more reliable or evidence easier to retain. It is not presented as proof of compliance by itself.
Scheduled evidence collection, naming, approval and retention workflows for recurring controls.
Access reviews, policy acknowledgements, exception approvals, corrective-action reminders and management reporting.
M365 and Google Workspace automation for onboarding, offboarding, reporting and controlled administrative workflows.
Clear boundaries are part of the service.