Information Security Risk and Treatment Plan

This product listing provides an overview of what can be covered with a day of remote support, spent on your information security risk work.

Seven hours of consultant time: your information assets recorded, the risks against them scored with a named owner, the treatment decided and written down, and the Statement of Applicability completed from that work rather than backwards.

A named consultant, files shared securely by Dropbox, and any control you have claimed but do not operate flagged before an auditor tests it.

To purchase go to Remote Support - Project, purchase 1 day (or more) of support and we will be in touch to discuss and plan your project.



ISO 27001 sounds like the hardest of them until you see the chain written down: what you hold, what could happen to it, what you have done about it. When this reaches me that chain is joined up, and the Statement of Applicability follows from something instead of being written to look complete.

Document Preparation
Prefer to Do It Yourself?

The ER15 Information Security Risks register, the F-Q14 Information Assets Matrix and the Statement of Applicability are all on the shelf, and Document Preparation will brand them for you.

Information Security Risk and Treatment Plan

ISO 27001 turns on one chain of documents. What information you hold, what could happen to it, what you have decided to do about that, and which of the Annex A controls you are applying and why. Get that chain right and the rest of the system follows. Get it wrong and every other document is describing a system that does not exist.

It is also the part organisations most often try to shortcut, usually by writing a Statement of Applicability first and working backwards. Auditors know what that looks like. This service builds the chain in the right order, around your actual systems.

What You Get

  • An information assets picture - the F-Q14 Information Assets Matrix completed with the data you hold, where it lives, who owns it and how it is classified
  • The ER15 Information Security Risks register built - your risks, scored, with the controls that apply and a named owner against each
  • The treatment recorded against every risk - what you are doing about it, what you have accepted and why, which is the treatment plan an auditor asks to see
  • Security incident and threat intelligence arrangements set up - so monitoring has somewhere to report and the register stays live rather than becoming a snapshot
  • The F-IMS26 Statement of Applicability completed - a decision recorded on every Annex A control, with the justification, drawn from the risk work rather than written to look complete
  • A supporting business risk assessment - the information security assessment matched to your shape, whether that is a small office, a virtual company or a larger organisation
  • Gaps flagged - a control you have claimed but do not operate comes back marked, because that is the one an auditor will test

How Much One Day Covers

The chain, end to end, for most organisations. There is no cap on the number of risks or assets. What moves the time is how complex your estate is - a cloud-only consultancy is a different job from a business with its own servers, a development team and a supply chain handling client data. The more context and information you give us, the better what we prepare will be. We work through as much as the time allows, in the order that matters most to you.

How the Work Gets Done

We use our own AI tooling to do the mechanical part of document preparation, and a consultant checks the output before it reaches you. On this chain the tooling does the joining up - carrying assets through into risks, risks through into treatment, and treatment through into the Statement of Applicability, so the four documents cannot say different things. Doing that by hand across 90-odd controls is where the day used to go, and it is the first thing to fall out of alignment the moment anything changes.

What your real risks are, and whether a control genuinely addresses one, is a consultant's judgement. So is the decision to accept a risk, which is a decision with consequences and is never made by tooling.

The templates and the register are ours, developed over 25 years of real audits, and they are not AI generated. Your risks come from your systems and your answers. We do not populate a risk register with generic threats you do not face, and we do not mark a control as applied because it would make the Statement of Applicability look better.

Why a Day Goes This Far

Anyone can rent the same AI we use. What they cannot rent is what we point it at.

Behind this service is a document library built over 25 years - manuals, procedures, policies, registers, risk assessments, COSHH assessments, audit checklists and forms, covering every standard we work to and most situations a management system runs into. Each one has been through real audits, and corrected where an assessor pushed back. That is the part that took 25 years, and it is the part that cannot be generated.

Our tooling applies that library to your business. A general purpose AI, pointed at the same job, has nothing to apply, so it writes something that reads well and describes a company that does not exist.

What We Need From You

  • What information you hold, particularly anything client, personal or commercially sensitive
  • Where it lives - cloud services, servers, laptops, phones, paper
  • Who has access, including contractors, associates and anyone outside the business
  • What you already have in place - backups, multi-factor authentication, device management, training
  • Any supplier or client security requirements you are contractually held to
  • Any existing risk register, asset list or Statement of Applicability

Other Things Remote Support Covers

A support day does not have to be spent on information security. The same day can be pointed at any one of these instead, and it is the same purchase either way:

A day can also go on things that are not document preparation at all - training, internal audits, a gap analysis, or simply working through a problem on a call. Remote Support - Project is the same day bought without a job attached to it.

Every one of these services is listed on the ISO consultancy support page, along with how a support day works and what is covered by a subscription.

There are currently no comments for this document.

Add a Comment

Please Login or Subscribe to add Comments.