Millecam

ISO 27001: an ISMS that actually works, not just on paper

The international standard for information security. Often a contractual requirement for clients or tenders, and a good reason to organise security structurally instead of ad hoc.

Who is this relevant for?

A client or tender requires it

ISO 27001 has become a contractual requirement from a client, insurer or tender, not (only) an internal priority.

Growing team, growing risk

Information security ran on ad-hoc agreements and loose documents. That no longer scales with the organisation.

The will is there, the time isn't

You know what an ISMS should look like, but no one on the team has the bandwidth to build it from scratch.

What Millecam does

A GAP analysis maps out where you stand today against ISO/IEC 27001:2022: per control, not in vague generalities. From there, the ISMS is built: scope, risk assessment, Statement of Applicability, policy and procedures that fit how the organisation actually works. Millecam also guides the final phase: internal audit, management review and the certification audit itself.

What you actually get

  • GAP analysis against ISO/IEC 27001:2022, scored per control
  • Scope definition of the ISMS (information security management system)
  • Risk assessment and risk treatment plan
  • Statement of Applicability
  • Policy documents and procedures, tailored to how the organisation actually works
  • Security objectives aligned with business operations
  • Collecting and structuring evidence
  • Internal audit preparation
  • Management review preparation
  • Guidance during the certification audit
  • Remediation of findings from audit or internal review

How an ISO 27001 track unfolds

Step 1

GAP analysis

Where you stand today against ISO/IEC 27001:2022, resulting in a concrete step-by-step plan.

Step 2

Implementation

ISMS scope, risk assessment, Statement of Applicability, policy and procedures: built, not just written.

Step 3

Certification

Internal audit, management review and guidance up to and during the certification audit.

More about the approach

Result

An ISMS an auditor can review without surprises: evidence that holds up, policy that's actually followed, and a certificate that demonstrates what actually happens, not just what is written on paper.

Why Millecam

One fixed point of contact, no rotating team. Direct contact with whoever does the work: pragmatic implementation instead of purely theoretical advice. More about Robin.

Ready to get started?

A no-obligation thirty-minute conversation is enough to determine whether, and how, Millecam can help.

Discuss your ISO 27001 track