ISO/IEC 27001 Consulting & Internal Audits

Build an ISMS that works.Be ready for certification.

Practical ISO/IEC 27001:2022 guidance from experienced cybersecurity, risk and compliance specialists.

Vectra helps organisations establish, improve and maintain an Information Security Management System—from initial scoping and gap assessment through risk treatment, internal audit, management review and independent certification readiness.

ISO 27001 support for organisations at every stage Gap AssessmentISMS DesignRisk AssessmentInternal AuditCertification Readiness
Information security management

More than policies. A management system for security risk.

ISO/IEC 27001 provides the requirements for establishing, implementing, maintaining and continually improving an ISMS. It helps organisations manage information-security risk systematically across people, processes, technology and suppliers.

01 / SCOPE

Define the ISMS boundary

Identify business services, locations, systems, information, interested parties and dependencies within scope.

02 / ASSESS

Understand information risk

Identify threats, vulnerabilities, consequences and existing controls using a repeatable risk methodology.

03 / TREAT

Implement proportionate controls

Select and justify controls, assign ownership and document treatment through the Statement of Applicability.

04 / IMPROVE

Operate the ISMS continually

Monitor objectives, audit performance, review changes and correct weaknesses throughout the certification cycle.

ISO 27001 services

Support from initial readiness to ongoing improvement.

Readiness

ISO 27001 gap assessment

Assess current governance, risk practices, documentation, controls and evidence against ISO/IEC 27001:2022.

Scoping

ISMS scope and context

Define organisational context, interested parties, scope boundaries, dependencies and information-security objectives.

Risk

Risk assessment and treatment

Establish methodology, complete risk assessment and develop a practical, owned risk-treatment plan.

Explore security assessments →
Design

ISMS framework and documentation

Create or refine policies, procedures, roles, governance, metrics, registers and evidence requirements.

Controls

Statement of Applicability

Select, justify and record applicable Annex A controls while connecting them to risk treatment and implementation evidence.

Audit

Internal ISMS audit

Independently test whether the ISMS conforms to organisational requirements and ISO/IEC 27001 and is effectively implemented.

Preparation

Certification readiness

Prepare evidence, address nonconformities, support management review and ready stakeholders for Stage 1 and Stage 2 audits.

Awareness

Training and organisational adoption

Build role-aware security understanding and support the competence and awareness obligations of the ISMS.

Explore awareness training →
Ongoing

ISMS management and improvement

Maintain registers, evidence, objectives, risk reviews, audit programmes and continual improvement after certification.

Current standard

ISO/IEC 27001:2022 with Amendment 1:2024.

ISO/IEC 27001:2022 is the current published edition. Amendment 1:2024 adds climate-action considerations to the organisation’s context and interested-party requirements. Organisations must determine whether climate change is relevant to the ISMS and consider relevant interested-party requirements.

01
Management-system clauses 4–10Context, leadership, planning, support, operation, performance evaluation and improvement remain the core certifiable requirements.
02
Risk-based control selectionAnnex A is a reference set, while the organisation selects controls based on information-security risk and records them in the Statement of Applicability.
03
Four Annex A control themesThe 2022 control set is organised into organisational, people, physical and technological themes.
04
Climate-action amendmentThe organisation must assess whether climate change is relevant to its context and whether interested parties have related requirements.
Annex A 2022

93 controls organised around four themes.

The Statement of Applicability records which controls are necessary, why they are included or excluded and their implementation status.

37Organisational controls

Governance, policy, responsibilities, suppliers, cloud services, incidents, continuity and compliance.

Annex A.5
8People controls

Screening, employment responsibilities, awareness, disciplinary processes and remote working.

Annex A.6
14Physical controls

Physical boundaries, secure areas, equipment, media, utilities, monitoring and secure disposal.

Annex A.7
34Technological controls

Identity, access, endpoint, cryptography, networks, development, logging, monitoring and resilience.

Annex A.8
Independent certification

Clear separation between preparation and certification.

Vectra can implement the ISMS, provide readiness services and conduct internal audits. Formal certification is performed by an independent accredited certification body.

Vectra Advisory + Internal Audit

Build, test and prepare the ISMS.

Vectra works with management and control owners to establish a practical ISMS and identify issues before the external certification audit.

  • Gap assessment and roadmap
  • Risk framework and Statement of Applicability
  • Policies, processes and evidence
  • Internal audit and remediation
  • Stage 1 and Stage 2 readiness
Accredited Certification Body

Perform the formal certification audit.

The certification body independently audits the ISMS and determines whether certification can be issued and maintained.

  • Stage 1 documentation and readiness audit
  • Stage 2 implementation and effectiveness audit
  • Certification decision
  • Surveillance audits
  • Recertification audit
Why Vectra

Compliance advice grounded in cybersecurity operations.

Vectra combines governance and assurance capability with technical security, managed services, architecture and testing experience. This helps ensure the ISMS reflects the actual environment—not just the documentation.

PracticalISMS design that can operate

Policies, processes and evidence designed around real teams, systems and business priorities.

TechnicalControls understood in context

Security specialists who understand cloud, endpoint, identity, network, development and managed operations.

IndependentObjective internal audits

Clear findings and evidence-based assessment without overstating compliance readiness.

IntegratedConnect multiple frameworks

Align ISO 27001 with PCI DSS, CPS 234, Essential Eight, NIST and customer assurance requirements.

End-to-EndAdvisory plus technical delivery

Access assessment, awareness, penetration testing and cybersecurity implementation capability.

OngoingMaintain the management system

Support risk reviews, evidence, internal audits, objectives and continual improvement after certification.

Delivery approach

A structured path from current state to certification readiness.

01

Discover

Understand the organisation, scope, stakeholders, systems and current maturity.

02

Assess

Complete gap and risk assessments and define the implementation roadmap.

03

Implement

Establish governance, controls, documentation, evidence and operational processes.

04

Audit

Conduct internal audit, management review and corrective-action follow-up.

05

Improve

Support certification readiness and maintain the ISMS through continual improvement.

Build a certifiable, sustainable ISMS

Turn ISO 27001 into an operating security programme.

Talk to Vectra about ISO/IEC 27001:2022 readiness, ISMS implementation, risk assessment, internal audit, certification preparation or ongoing compliance support.

Start with an ISO 27001 readiness discussion

Tell us whether you are starting from scratch, transitioning an existing ISMS or preparing for an upcoming audit.

Contact the Compliance Team →