Free consultation

ISO/IEC27001

Information Security Management System (ISMS)

ISO 27001 Consulting
Information Security Management

We build an ISMS to ISO/IEC 27001:2022 sized to your organisation — from risk assessment to the day the auditor arrives — so your team can run it on its own after certification.

Current edition of the standard
2022
Controls in Annex A
93
Control themes
4
Certificate cycle, audited yearly
3 yrs

What is ISO 27001?

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It requires an organisation to identify risks to its information, choose appropriate controls, and keep reviewing and improving them.

The core requirements are clauses 4 to 10. Annex A lists 93 controls in four themes — organizational (37), people (8), physical (14) and technological (34). Controls are selected based on the risk assessment, and the reasoning is recorded in the Statement of Applicability (SoA).

Certificates are issued by an independent certification body, last three years, and include a surveillance audit every year.

Deliverables

What you get

  • Gap analysis report and a clearly defined certification scope
  • Information asset register, risk register and risk treatment plan
  • Statement of Applicability covering all 93 controls, with the reason for each decision
  • Information security policy, procedures and forms people actually use
  • Security awareness training for staff, with training records
  • Internal audit and management review
  • Support during the Stage 1 and Stage 2 certification audits, and help closing findings

ISO/IEC 27001

The four themes of Annex A

Not every control has to be applied, but every one must be considered and the decision recorded in the SoA.

Organizational · 37 controls

Policies, roles, asset management, access control, suppliers, incident management and business continuity.

People · 8 controls

Screening, confidentiality agreements, awareness training, disciplinary process and remote working.

Physical · 14 controls

Secure areas, entry control, equipment protection and secure disposal of storage media.

Technological · 34 controls

Authentication, cryptography, backup, logging and monitoring, vulnerability management and secure development.

Our Process

From day one to the day the auditor walks in

Every project follows these five steps. Timing depends on your size and scope — you’ll get a firm timeline once the readiness assessment is done.

  1. Gap analysis

    Compare your current practice with the requirements and define the certification scope.

    ~2–4 weeks
  2. System design

    Write policies, procedures, forms and a risk register people will actually use.

    ~1–3 months
  3. Rollout & training

    Train your team and build up complete records and evidence.

    ~1–3 months
  4. Internal audit

    Audit internally, fix nonconformities and hold the management review.

    ~2–4 weeks
  5. Certification audit

    We stand beside you through the certification body’s or assessor’s audit until you’re certified.

    per auditor schedule

Consultants cannot issue certificates — certificates come from an independent Certification Body. We help you choose one and make sure everything is ready.

FAQ

Frequently asked questions

How long does ISO 27001 take?

Most small and mid-sized organisations take about 4–9 months from kickoff to audit-ready, depending on scope, existing documentation and how much time the team can give.

Do we have to apply all 93 controls?

No. Controls are selected based on your risk assessment and scope, but every control must be considered, and exclusions justified in the Statement of Applicability.

We are still on ISO 27001:2013. What now?

The transition period from the 2013 edition ended in October 2025, so 2013 certificates are no longer valid. The system has to move to the 2022 edition, which adds 11 new controls such as threat intelligence and secure coding.

What happens after certification?

The system has to keep working: the certification body returns for a surveillance audit every year and recertifies in year three. We offer ongoing support, and Evidosa can track evidence that is about to expire.

Contact

Start with a free one-hour ISO 27001 readiness assessment

Address
42/135 Chit Aree Ville 5, Lampang–Ngao Highway Rd., Chomphu, Mueang Lampang, Lampang 52100, Thailand

Call or email us and tell us where your organisation stands. We’ll tell you which standard to start with, roughly how long it will take, and what you need to prepare.

Tax ID
0525568001095