Information Security Management

Prepare for ISO/IEC 27001 certification.

Turn security from a collection of tools into an owned information security management system.

From ambition to an auditable management system.

39Security helps your organisation design, implement and improve the management system required by ISO/IEC 27001:2022. We focus on practical ownership, evidence and processes that work in normal business operations, not a collection of documents created only for audit day.

Support can include

  • ISMS scope and context
  • Risk assessment and treatment plan
  • Policies, control ownership and evidence
  • Statement of Applicability support
  • Internal audit, management review and certification preparation

A proportionate implementation route

  1. Discovery and scope: understand services, information, AI use, interested parties and business objectives.
  2. Gap review: map current practices and evidence against the standard's requirements.
  3. Implementation: create the required controls, ownership, records and operating rhythm.
  4. Internal assurance: perform internal audit, corrective actions and management review preparation.
  5. Certification support: prepare for Stage 1 and Stage 2 assessment with an independent certification body.

Important certification distinction

39Security provides readiness, implementation and improvement consultancy. ISO does not certify organisations, and 39Security does not award the certificate. Certification is performed by an independent certification body, ideally one accredited by the relevant national accreditation body.

Read the official ISO overview for ISO/IEC 27001:2022 →

Gap review

Evidence-based review of current practice, documented gaps, owners and recommended priorities.

Implementation support

Policies, processes, risk work, records and operational routines tailored to the organisation.

Certification preparation

Internal audit support, management review readiness and practical preparation for independent assessment.