ISO 27001 sounds like the hardest of them until you see the chain written down: what you hold, what could happen to it, what you have done about it. When this reaches me that chain is joined up, and the Statement of Applicability follows from something instead of being written to look complete.
Further guidance on information security risk:
Information Security Risk and Treatment Plan
ISO 27001 turns on one chain of documents. What information you hold, what could happen to it, what you have decided to do about that, and which of the Annex A controls you are applying and why. Get that chain right and the rest of the system follows. Get it wrong and every other document is describing a system that does not exist.
It is also the part organisations most often try to shortcut, usually by writing a Statement of Applicability first and working backwards. Auditors know what that looks like. This service builds the chain in the right order, around your actual systems.
What You Get
- An information assets picture - the F-Q14 Information Assets Matrix completed with the data you hold, where it lives, who owns it and how it is classified
- The ER15 Information Security Risks register built - your risks, scored, with the controls that apply and a named owner against each
- The treatment recorded against every risk - what you are doing about it, what you have accepted and why, which is the treatment plan an auditor asks to see
- Security incident and threat intelligence arrangements set up - so monitoring has somewhere to report and the register stays live rather than becoming a snapshot
- The F-IMS26 Statement of Applicability completed - a decision recorded on every Annex A control, with the justification, drawn from the risk work rather than written to look complete
- A supporting business risk assessment - the information security assessment matched to your shape, whether that is a small office, a virtual company or a larger organisation
- Gaps flagged - a control you have claimed but do not operate comes back marked, because that is the one an auditor will test
How Much One Day Covers
The chain, end to end, for most organisations. There is no cap on the number of risks or assets. What moves the time is how complex your estate is - a cloud-only consultancy is a different job from a business with its own servers, a development team and a supply chain handling client data. The more context and information you give us, the better what we prepare will be. We work through as much as the time allows, in the order that matters most to you.
How the Work Gets Done
We use our own AI tooling to do the mechanical part of document preparation, and a consultant checks the output before it reaches you. On this chain the tooling does the joining up - carrying assets through into risks, risks through into treatment, and treatment through into the Statement of Applicability, so the four documents cannot say different things. Doing that by hand across 90-odd controls is where the day used to go, and it is the first thing to fall out of alignment the moment anything changes.
What your real risks are, and whether a control genuinely addresses one, is a consultant's judgement. So is the decision to accept a risk, which is a decision with consequences and is never made by tooling.
The templates and the register are ours, developed over 25 years of real audits, and they are not AI generated. Your risks come from your systems and your answers. We do not populate a risk register with generic threats you do not face, and we do not mark a control as applied because it would make the Statement of Applicability look better.
Why a Day Goes This Far
Anyone can rent the same AI we use. What they cannot rent is what we point it at.
Behind this service is a document library built over 25 years - manuals, procedures, policies, registers, risk assessments, COSHH assessments, audit checklists and forms, covering every standard we work to and most situations a management system runs into. Each one has been through real audits, and corrected where an assessor pushed back. That is the part that took 25 years, and it is the part that cannot be generated.
Our tooling applies that library to your business. A general purpose AI, pointed at the same job, has nothing to apply, so it writes something that reads well and describes a company that does not exist.
What We Need From You
- What information you hold, particularly anything client, personal or commercially sensitive
- Where it lives - cloud services, servers, laptops, phones, paper
- Who has access, including contractors, associates and anyone outside the business
- What you already have in place - backups, multi-factor authentication, device management, training
- Any supplier or client security requirements you are contractually held to
- Any existing risk register, asset list or Statement of Applicability
Other Things Remote Support Covers
A support day does not have to be spent on information security. The same day can be pointed at any one of these instead, and it is the same purchase either way:
A day can also go on things that are not document preparation at all - training, internal audits, a gap analysis, or simply working through a problem on a call. Remote Support - Project is the same day bought without a job attached to it.
Every one of these services is listed on the ISO consultancy support page, along with how a support day works and what is covered by a subscription.