From ambition to an auditable management system.
39Security helps your organisation design, implement and improve the management system required by ISO/IEC 27001:2022. We focus on practical ownership, evidence and processes that work in normal business operations, not a collection of documents created only for audit day.
Support can include
- ISMS scope and context
- Risk assessment and treatment plan
- Policies, control ownership and evidence
- Statement of Applicability support
- Internal audit, management review and certification preparation
A proportionate implementation route
- Discovery and scope: understand services, information, AI use, interested parties and business objectives.
- Gap review: map current practices and evidence against the standard's requirements.
- Implementation: create the required controls, ownership, records and operating rhythm.
- Internal assurance: perform internal audit, corrective actions and management review preparation.
- Certification support: prepare for Stage 1 and Stage 2 assessment with an independent certification body.
Important certification distinction
39Security provides readiness, implementation and improvement consultancy. ISO does not certify organisations, and 39Security does not award the certificate. Certification is performed by an independent certification body, ideally one accredited by the relevant national accreditation body.