An ISO 27001 gap assessment evaluates an organization’s current information security practices against global standards, pinpointing strengths and areas for improvement before pursuing full certification.
- Initial Consultation: Discuss your business’s objectives, scope of the assessment, and current information security posture.
- Documentation Review: Evaluate existing security policies, procedures, and controls to determine alignment with ISO 27001 requirements.
- On-site Assessment: Our team visits your facility (or connects with you remotely) to gain a deeper understanding of your operations, interact with relevant personnel, and observe your processes in action.
- Gap Analysis: Identify areas where your organization meets ISO 27001 standards and highlight where improvements are required.
- Feedback & Recommendations: Receive a comprehensive report detailing findings and actionable recommendations for aligning with ISO 27001 requirements.
For an organization to pursue ISO 27001 certification they need to establish a robust Information Security Management System (ISMS) that addresses management clauses, including leadership commitment, risk assessment, and continuous improvement, as well as satisfying all the requirements of Annex A, which consists of specific security controls across domains like access control, cryptography, human resource security, and operations security. Fortreum can step-in and assist you in executing a program to develop the necessary artifacts for ISO 27001 certification.
At Fortreum, we’re committed to the highest standards of excellence and are currently in the midst of our accreditation process. While we do not offer certification services at this moment, our roadmap is set for early 2024. If your company is interested in participating in our witness audit for accreditation, we’re offering our assessment services at a reduced fee.
Continuous Monitoring is a critical part of maintaining the security controls, practices, and processes necessary to safeguard Controlled Unclassified Information (CUI) and your organization’s sensitive information.
- Develop a set of objectives and desired outcomes for continuous assurance
- Schedule project activities that align to these objectives
- Implement measurement capabilities to ensure ongoing compliance is maintained within the certification boundary
- Assess changes to your environment that could impact your certification status and boundary.