Included depending on scope
- Assessment and roadmap
- ISMS documentation
- Support implementing controls
- Preparation for the certification audit
We help strengthen controls and prepare an information security management system (ISMS) that fits your company's situation.
It involves defining the management system's scope, assessing risk, selecting and documenting controls, assigning owners and producing evidence that they work.
ISO/IEC 27001 readiness consulting is not the issuance of an organizational certification: certification is granted by an accredited certification body.
Rubén Castillo, who leads LandoHOUSE, earned the CertiProf ISO/IEC 27001 Internal Auditor certification (valid 2020–2023). See credentials
Gaps against applicable requirements and controls.
Scope, risks, policies and statement of applicability.
Controls, owners, evidence and awareness.
Internal audit and management review.
Security program leadership.
View solutionIT controls assessment.
View solutionA 12-question self-assessment.
View solutionNo. We support readiness; certification is issued by an independent, accredited certification body.
No. The system is sized to the chosen scope and can start with the most critical processes or services.
CISO as a Service can lead the security program and report ISMS implementation progress to leadership.
Which process, risk or opportunity does your company need to address? Let's talk to understand your situation and define the next step.