Skip to main content

Supported engagement

ISO 27001 support: building the evidence.

You are preparing an ISO 27001 certification, but the controls, the evidence and the responsibilities of the information security management system (ISMS) are not yet tied to the target scope. We identify the gaps, implement the agreed controls and organise a dated evidence file.

Describe your ISO 27001 preparation

From scope to mock audit

Move from gap to control, then to evidence.

  1. 01

    Gap analysis

    Which controls are in place, missing or insufficiently documented within the target scope?

    Record: Dated gap matrix

  2. 02

    Treatment plan

    Which actions must be ordered, assigned and tracked?

    Record: Ordered treatment plan

  3. 03

    Technical controls

    How does each agreed measure become a verifiable mechanism?

    Record: Controls implemented and documented

  4. 04

    Evidence

    How do you collect and review evidence without relying on one-off searches?

    Record: Organised and dated evidence file

  5. 05

    Mock audit

    Which gaps remain to be addressed before the assessment?

    Record: Report and remaining actions

Identity and access management (IAM), permissions and access reviews form one control domain of the project.

Who decides, who implements.

We implement the agreed controls. Your organisation decides the scope, holds the ISMS responsibilities and leads the assessment relationship.

Engagement scope

CTN Solutions

We document the existing setup, its dependencies and its technical limits.

Organisation

The organisation decides the scope and appoints its owners.

Acceptance

Scope and responsibilities recorded.

Technical measures

CTN Solutions

We implement the agreed controls on the infrastructure.

Organisation

The organisation owns the organisational and documentary measures.

Acceptance

Controls reviewed and entered in the register.

Evidence collection

CTN Solutions

We organise a repeatable, dated collection.

Organisation

The organisation approves the access and the sensitivity of the items exposed.

Acceptance

Evidence file organised and verifiable.

Internal audit preparation

CTN Solutions

We prepare the technical items for the separate audit engagement.

Organisation

The organisation schedules the internal audit in its programme.

Acceptance

Technical items available for the audit.

Certification assessment

CTN Solutions

We prepare the agreed technical answers and evidence.

Organisation

The organisation chooses the certification body and leads the assessment relationship.

Acceptance

Technical file presented at the assessment.

Deliverables, required access and responsibilities.

What we prepare

  • Gap matrix and treatment plan
  • Technical controls implemented and documented
  • Organised and dated evidence file
  • Mock audit report and remaining actions

What we need from you

  • The target standard and scope
  • A named ISMS owner
  • Access to the systems concerned
  • Control owners available to make decisions

Separate engagements

  • Organisational measures assigned to the ISMS owners
  • Internal audit, handled in a separate audit engagement
  • Ongoing operation of the controls after handover

Certification

Certification audits are reserved for bodies accredited under ISO/IEC 17021-1 (COFRAC in France). CTN Solutions does not issue certificates.

Independence

An auditor must not audit their own work. If CTN Solutions built your information security management system (ISMS), the internal audit of that same ISMS is assigned to a third party or subject to an established and documented separation of roles.

Scope to define

Describe your ISO 27001 preparation.

Tell us the target standard, the state of the ISMS, the assessment deadline and the systems concerned. We use this to define the engagement, the access and the technical responsibilities.

Describe what you need to achieve, the system concerned and what prevents progress today.

Security check

The check loads when you start the form.

Without JavaScript, use the email link below to send your request.