ISO 27001: an ISMS that actually works, not just on paper
The international standard for information security. Often a contractual requirement for clients or tenders, and a good reason to organise security structurally instead of ad hoc.
Who is this relevant for?
A client or tender requires it
ISO 27001 has become a contractual requirement from a client, insurer or tender, not (only) an internal priority.
Growing team, growing risk
Information security ran on ad-hoc agreements and loose documents. That no longer scales with the organisation.
The will is there, the time isn't
You know what an ISMS should look like, but no one on the team has the bandwidth to build it from scratch.
What Millecam does
A GAP analysis maps out where you stand today against ISO/IEC 27001:2022: per control, not in vague generalities. From there, the ISMS is built: scope, risk assessment, Statement of Applicability, policy and procedures that fit how the organisation actually works. Millecam also guides the final phase: internal audit, management review and the certification audit itself.
What you actually get
- GAP analysis against ISO/IEC 27001:2022, scored per control
- Scope definition of the ISMS (information security management system)
- Risk assessment and risk treatment plan
- Statement of Applicability
- Policy documents and procedures, tailored to how the organisation actually works
- Security objectives aligned with business operations
- Collecting and structuring evidence
- Internal audit preparation
- Management review preparation
- Guidance during the certification audit
- Remediation of findings from audit or internal review
How an ISO 27001 track unfolds
Step 1
GAP analysis
Where you stand today against ISO/IEC 27001:2022, resulting in a concrete step-by-step plan.
Step 2
Implementation
ISMS scope, risk assessment, Statement of Applicability, policy and procedures: built, not just written.
Step 3
Certification
Internal audit, management review and guidance up to and during the certification audit.
Result
An ISMS an auditor can review without surprises: evidence that holds up, policy that's actually followed, and a certificate that demonstrates what actually happens, not just what is written on paper.
Why Millecam
One fixed point of contact, no rotating team. Direct contact with whoever does the work: pragmatic implementation instead of purely theoretical advice. More about Robin.
Ready to get started?
A no-obligation thirty-minute conversation is enough to determine whether, and how, Millecam can help.
Discuss your ISO 27001 track