ISO/IEC 27001

Prepare your organization to work toward ISO/IEC 27001.

We assess the current state, identify gaps and build a readiness roadmap for ISO/IEC 27001, without presenting readiness as certification.

Why this matters

Preparation requires more than a control checklist

You need to know what exists, what is missing, what evidence is available and which actions should come first.

Gaps between current practices and the target framework

Scattered or incomplete evidence

Controls without clear ownership

Difficulty building a preparation plan

AEGRIX approach

Readiness with gaps and priorities

Within the agreed scope, we assess capabilities, evidence and gaps and turn them into a preparation roadmap.

Typical deliverables

  • Current-state assessment
  • Gap map
  • Action prioritization
  • Evidence matrix
  • Readiness roadmap

ISO/IEC 27001:2022

Readiness across the ISMS and controls

Preparation considers management-system requirements and the controls needed to address risk, with comparison against the Annex A reference set.

Clauses 4–5

Organizational context, interested parties, scope, leadership, policy and responsibilities.

Clause 6

Planning, risks and opportunities, security objectives and risk treatment.

Clauses 7–10

Support, operation, performance evaluation and continual improvement of the ISMS.

Annex A

Comparison of necessary controls against the information security controls reference set.

Process

From current state to roadmap

01 · Scope

We define the organization, processes and boundaries of the assessment.

02 · Current state

We review existing practices, controls and available evidence.

03 · Gaps

We identify differences against the agreed readiness criteria.

04 · Roadmap

We order the actions needed to move forward.

Next step

Want to understand your readiness?

Let’s discuss the scope and evidence available in your organization.

Talk to AEGRIX