Information security

Build an information security management system that works.

ISO/IEC 27001 sets requirements for an information security management system (ISMS). We help establish the scope, governance, risk treatment, controls, and improvement cycle needed for an effective program and an independent certification assessment.

Our implementation focus

Make the requirements operational.

  1. 01

    Define ISMS scope and interested parties

  2. 02

    Run a risk assessment and treatment process

  3. 03

    Design policies, control ownership, and the Statement of Applicability

  4. 04

    Operate controls and collect evidence

  5. 05

    Prepare management review, internal audit, and corrective action

Independent assessment

Certification decisions are made by an independent certification body. Advisory work does not guarantee certification.

Questions we hear

Get the distinctions right.

What does the Statement of Applicability do?

It records the controls selected for the ISMS, the reasons for inclusion or exclusion, and implementation status. It should reflect the risk treatment process and actual scope rather than a generic checklist.

Can ISO/IEC 27001 work be reused for SOC 2?

Risk, access, change, supplier, incident, and review processes can be shared where the system boundaries overlap. A SOC 2 report still needs its own service description, criteria, period, and independent CPA examination.

Does a certificate cover every product?

No. The certificate and its scope statement identify the assessed management system. Buyers should compare that scope with the service they plan to use.

Work with Normstone

Build a defensible path to readiness.

Tell us the outcome you need and the markets involved. We’ll help define the work.

Start a conversation