ISO 27000 Consultancy

Build a robust Information Security Management System

ISO 27000 Consultancy

ISO 27001 is the global best-practice standard for information security. Gaining compliance with — or certification to — ISO 27001 proves that your organization takes the confidentiality, integrity and availability of its information seriously.

The ability to respond quickly to information-security breaches or incidents is one of the key goals of ISO 27001. Minimizing the opportunity for incidents also gives your organization a major advantage in service resilience and helps build confidence in your ability to handle information securely.

Magellanix offers a modular programme of consultancy. Our methodology enables the development of a robust Information Security Management System (ISMS).

What is ISO 27000?

ISO 27001:2013 is the de-facto international standard on establishing, operating and maintaining an Information Security Management System (ISMS). The standard is structured into two sections: mandatory sections detailing specific processes and policies that must be adhered to in order to gain formal certification, and Annex A — covering 14 security guiding principles.

Self vs. Formal Certification

An organization can claim self-compliance to the standard — meaning it operates an ISMS but is not pursuing formal certification. It may still be subject to audits by customers or clients who impose a compliance requirement through contractual clauses or the tender process. Self-compliance provides a common basis for developing organizational security standards and confidence in inter-organizational dealings.

Formal certification is awarded by independent third-party certification bodies. A certified organization is subject to six-monthly surveillance audits and re-certification audits every 3 years — ensuring continual monitoring and improvement of its ISMS.

Benefits

A formally documented ISMS, independently assessed, demonstrates to customers and clients that your organization is committed to security and can handle information securely. This increases trust in your brand and image. The reputation of ISO and certification against the internationally recognized ISO 27001:2013 standard enhances credibility and may increase market share.

Successful certifications

Magellanix's modular programme consists of the following phases:

  • Phase 1: Initial Scoping Meeting
  • Phase 2: Gap Analysis / Risk Assessment / Security Improvement Plan
  • Phase 3: Implement Security Improvements (Plan)
  • Phase 4: Information Security Education and Training
  • Phase 5: Implementation Review and Compliance Checks
  • Phase 6: Final Mock Certification

Magellanix has a 100% success rate in assisting organizations through ISO 27001. Having gained certification ourselves, we are particularly well placed to guide others toward this internationally recognized standard.

Our business consultants are all ISO 27001:2013 Information Security Management experts — including ISO 27001:2013 Lead Auditors, ISACA CISA & CISM qualified professionals, and CISSP-certified members of ISC2.org.