Information security is not only about technical solutions. It requires clear responsibilities, ongoing risk assessments and processes that protect the company's information and support its operations. 

ISO 27001 provides an internationally recognised framework for an information security management system. The standard can be used as the basis for the company's security programme, whether the objective is certification, improved risk management or assurance for customers. 

RSM helps you gain an overview, identify gaps and establish an information security framework tailored to your company, risks and customer requirements. 

How we help you 

We can help you to: 

  • define the scope and map critical information, systems and suppliers 
  • perform a GAP assessment against ISO 27001 
  • identify and prioritise information security risks 
  • establish governance, roles and management reporting 
  • develop and implement relevant policies, processes and controls 
  • strengthen incident management, access management, supplier management and resilience 
  • prepare the company for external ISO 27001 certification 

The aim is not to establish more documentation than necessary. The aim is an operational management system that supports the company's operations and can be maintained over time. 

From GAP assessment to an operational security framework.

A typical engagement consists of four steps: 

1. Clarification and scope 

We clarify the company's needs, risk profile and customer requirements and determine which parts of the organisation are to be included. 

2. GAP assessment 

We assess your existing processes, controls and documentation against ISO 27001 and other relevant requirements. 

3. Roadmap and implementation 

You receive a prioritised plan and, if required, we help establish the necessary processes, controls and documentation. 

4. Follow-up and improvement 

We help embed information security as an ongoing management process involving risk assessments, controls, reporting and improvement. 

ISO 27001 or an ISAE or SOC report? 

ISO 27001 certification demonstrates that the company has established an information security management system. However, the certificate does not normally provide customers with a detailed description of the individual controls, the auditor's testing or the results of the testing. 

Where customers or their auditors require detailed assurance regarding information security controls, an ISAE 3000 or SOC 2 report may be relevant. ISAE 3402 is relevant where the controls in scope may affect customers' financial reporting. 

The choice depends on customer requirements, the intended use and the desired level of assurance. 

Advisory services and any subsequent assurance engagement are planned in accordance with the applicable auditor independence requirements. 

You may also wish to read about ISO 27001 certification and ISAE and SOC reports. 

Find out where you stand 

Contact us for an initial discussion about your information security, most significant gaps and need for ISO 27001 or assurance for customers.