Supported engagement
ISO 27001 support: building the evidence.
You are preparing an ISO 27001 certification, but the controls, the evidence and the responsibilities of the information security management system (ISMS) are not yet tied to the target scope. We identify the gaps, implement the agreed controls and organise a dated evidence file.
Describe your ISO 27001 preparationFrom scope to mock audit
Move from gap to control, then to evidence.
- 01
Gap analysis
Which controls are in place, missing or insufficiently documented within the target scope?
Record: Dated gap matrix
- 02
Treatment plan
Which actions must be ordered, assigned and tracked?
Record: Ordered treatment plan
- 03
Technical controls
How does each agreed measure become a verifiable mechanism?
Record: Controls implemented and documented
- 04
Evidence
How do you collect and review evidence without relying on one-off searches?
Record: Organised and dated evidence file
- 05
Mock audit
Which gaps remain to be addressed before the assessment?
Record: Report and remaining actions
Identity and access management (IAM), permissions and access reviews form one control domain of the project.
Who decides, who implements.
We implement the agreed controls. Your organisation decides the scope, holds the ISMS responsibilities and leads the assessment relationship.
Engagement scope
CTN Solutions
We document the existing setup, its dependencies and its technical limits.
Organisation
The organisation decides the scope and appoints its owners.
Acceptance
Scope and responsibilities recorded.
Technical measures
CTN Solutions
We implement the agreed controls on the infrastructure.
Organisation
The organisation owns the organisational and documentary measures.
Acceptance
Controls reviewed and entered in the register.
Evidence collection
CTN Solutions
We organise a repeatable, dated collection.
Organisation
The organisation approves the access and the sensitivity of the items exposed.
Acceptance
Evidence file organised and verifiable.
Internal audit preparation
CTN Solutions
We prepare the technical items for the separate audit engagement.
Organisation
The organisation schedules the internal audit in its programme.
Acceptance
Technical items available for the audit.
Certification assessment
CTN Solutions
We prepare the agreed technical answers and evidence.
Organisation
The organisation chooses the certification body and leads the assessment relationship.
Acceptance
Technical file presented at the assessment.
Deliverables, required access and responsibilities.
What we prepare
- Gap matrix and treatment plan
- Technical controls implemented and documented
- Organised and dated evidence file
- Mock audit report and remaining actions
What we need from you
- The target standard and scope
- A named ISMS owner
- Access to the systems concerned
- Control owners available to make decisions
Separate engagements
- Organisational measures assigned to the ISMS owners
- Internal audit, handled in a separate audit engagement
- Ongoing operation of the controls after handover
Certification
Independence
Scope to define
Describe your ISO 27001 preparation.
Tell us the target standard, the state of the ISMS, the assessment deadline and the systems concerned. We use this to define the engagement, the access and the technical responsibilities.