ISO 27001

ISO 27001 Consultancy for UK Organisations

A right-sized information security management system built around how your organisation actually works, prepared for audit by an accredited certification body.

Overview

Our Approach to ISO 27001

ISO 27001 is achievable for an SME when the management system is sized to the organisation rather than copied from a template written for a multinational. Cloud Agile operates its own independently certified ISO/IEC 27001 information security management system, and we use that practical experience to help clients build theirs: scope, risk, controls, evidence and audit readiness.

What's Included

Everything You Need From ISO 27001

  • ISMS scope definition and leadership responsibilities
  • Information-security risk assessment and risk treatment
  • Statement of Applicability and control selection
  • Policies, procedures and supporting records
  • Asset, supplier and access management
  • Internal audit support, management review and certification readiness

Scope, leadership and risk

Scope determines the size of everything that follows. We define it deliberately, around the services, locations and information that matter, and make sure leadership responsibilities are real rather than nominal.

  • Scope statement covering services, locations, people and systems
  • Interested parties and the requirements they place on you
  • Roles, responsibilities and management commitment
  • Risk assessment methodology that your team can actually repeat
  • Risk register with owners, treatments and review dates
  • Statement of Applicability justifying each control decision

Policies, controls and evidence

Auditors look for a system that is used, not a folder of documents. We write policies that match your working practices, then implement the technical and organisational controls behind them.

  • Policy set proportionate to the organisation, not a generic library
  • Access control, asset management and supplier assurance
  • Technical controls across identity, endpoints, cloud and infrastructure
  • Incident management, business continuity and change processes
  • Evidence and records generated by routine operation rather than retrofitted
  • Awareness and training records

Audit readiness and continual improvement

Certification is awarded by an independent accredited certification body following a formal two-stage audit. Cloud Agile provides consultancy and readiness work; we do not audit or award certification.

Once certified, the system has to keep running: internal audits, management reviews, corrective actions and surveillance audits are part of the ongoing commitment, and we support that cycle.

  • Internal audit programme and support in running it
  • Management review agenda, inputs and records
  • Corrective action and nonconformity handling
  • Preparation for stage one and stage two certification audits
  • Support during surveillance audits and continual improvement
Delivery

How a Project Works

  1. 1

    Scope

    Define the ISMS boundary, leadership responsibilities and objectives.

  2. 2

    Assess risk

    Run the risk assessment, agree treatments and build the Statement of Applicability.

  3. 3

    Implement

    Put policies, processes and technical controls in place and start generating evidence.

  4. 4

    Audit internally

    Run internal audits and management review, then correct what they find.

  5. 5

    Certify and improve

    Prepare for the certification audit and keep the system running afterwards.

Why It Matters

The Outcomes You'll Actually See

Sized to your organisation

A management system proportionate to the business, which is the only kind that survives contact with daily work.

Built by a certified organisation

We run our own independently certified ISO/IEC 27001 ISMS, so the advice is grounded in doing it, not just reading it.

Evidence as a by-product

Controls are implemented so routine operation produces the records auditors ask for.

What Success Looks Like

  • A defined ISMS scope with real leadership ownership
  • A working risk assessment, treatment plan and Statement of Applicability
  • Policies, controls and evidence aligned to how you operate
  • Readiness for an independent certification audit, and support afterwards

Related services

FAQs

Frequently Asked Questions

Does Cloud Agile award ISO 27001 certification?+

No. Certification is awarded by an independent accredited certification body following a formal audit. We provide consultancy, implementation and readiness support, and we support you through the audit process.

Is Cloud Agile itself certified?+

Yes. We operate our own independently certified ISO/IEC 27001 information security management system, which is one reason our advice is practical rather than theoretical.

How long does ISO 27001 take?+

For an SME starting from a reasonable security baseline it is typically several months of implementation before the certification audit, depending on scope, resource availability and how much needs building from scratch.

We already have Cyber Essentials. Does that help?+

It helps with several technical controls and shows a baseline is in place, but ISO 27001 is a management system covering risk, governance and process as well. The existing work is reused wherever it applies.

Ready to Elevate Your Managed IT Services?

Book a 20-minute strategy call. We'll pressure-test where technology is holding your business back, and map out how a stronger IT partnership unlocks growth.