A working ISMS

How do you build an ISMS that demonstrably works?

Kynexis Information Security guides you from scope and risk analysis to policies, measures, evidence, internal audit and management assessment. The result is an ISMS that is in line with daily practice and can be prepared for an independent certification audit.

Do you recognize this?
  • ISO 27001 documents grow, but ownership and daily execution remain behind.
  • Implementation is with one specialist, while processes and measures are intended to work organisation-wide.
  • Teams do not know enough what evidence is needed and how checks are carried out.
  • You want to certify without building an ISMS paper that stops after the audit.

What are the risks? Without workable implementation, ISO 27001 will become a documentation project. This takes a lot of time, while management and employees cannot steer and work with it.

Our promise of service

ISO 27001 guidance connecting documentation and practice

Kynexis Information Security helps you implement ISO 27001 at a pace and form that suits your organisation, with clear owners, useful evidence and permanent security.

  • Workable scope and risk approach
  • Measures with ownership and proof
  • Preparation for internal and certification audit

ISO 27001 implementation support

What is ISO 27001 guidance?

Kynexis Information Security guides you from scope and risk analysis to policies, measures, evidence, internal audit and management assessment. The result is an ISMS that is in line with daily practice and can be prepared for an independent certification audit.

FOR WHOMFor certification ambition
WHENA management system that helps the organisation to steer
RESULTA demonstrable ISMS ready for independent review

When does this service fit?

A management system that helps the organisation to steer

This guidance fits when the ambition is clear and the organisation wants to actually organise or improve the ISMS. An ISO 27001 GAP analysis can determine the starting position in advance. The implementation then focuses on coherence, implementation and evidence.

For certification ambitionFor a professional ISMSFor internal control and customer confidence

Implementation areas

All building blocks of ISO 27001 in workable coherence

Existing processes and documents are used as much as possible. Only what is necessary for control, operation and detection is added.

Context and Scope

Identifying organisational context, stakeholders, processes, locations and boundaries of ISMS.

Risks and treatment

Practically organise methodology, risk analysis, treatment plan and acceptance criteria.

Policy and responsibilities

Policy, roles, objectives and decision making are linked to the organisation.

Annex A and Application

Select, support and define measures in the Applicability Declaration.

Operation and evidence

Organise checks, registrations, suppliers' agreements and supporting documents in a cyclical manner.

Evaluation and improvement

Perform internal audit, management review, deviations and corrective actions.

Your result

A demonstrable ISMS ready for independent review

You have a coherent management system with clear owners, current risks and demonstrable execution. Kynexis Information Security prepares the organisation for content; the certification audit and the certificate shall remain with an independent certification body.

  • Clear ISM scope and governance
  • Current risk analysis and treatment plan
  • Declaration of Applicability
  • Operational controls and structured evidence
  • Internal audit, management review and improvement cycle
KYNEXISISO 27001 implementation support
AScope defined14Actions in progress2Decisions necessary
FocusWorking processes and evidenceRisk-driven and enforceable

How we work

Phased building with clear owners

  1. 01

    Start and GAP

    To determine ambition, scope, starting position and project design.

  2. 02

    Design

    Develop a risk approach, policy, roles, measures and evidence structure.

  3. 03

    Implement

    Perform processes, involve employees and build evidence of operation.

  4. 04

    Keys and preparations

    Perform internal audit and management review and finish open points.

Preparation for certification

A logical route with independent roles

Kynexis Information Security guides implementation and preparation. The certification body shall then independently carry out the certification audit.

01 GAP

ISO 27001 GAP Analysis

To determine what's already in place and what's still needed.

View this phase →
02 DESIGN

ISMS device

Bringing together risks, policies, roles and measures.

04 EVALUATION

Internal audit

Objective assessment and completion of improvement points.

05 CERTIFICATION

Independent audit

Certification by an appropriate body.

Make your next step concreteISO 27001 support needed?

Discuss your current situation, certification target and the support needed to make it work demonstrably.

Plan a guidance interview

Frequently Asked Questions

Practical answers on ISO 27001 implementation support

What does ISO 27001 include?

The guidance includes the design and operation of ISMS: Scope, governance, risk analysis, risk management, policies, measures, evidence, internal audit, management review and continuous improvement.

Can Kynexis issue the ISO 27001 certificate?

No. Kynexis Information Security guides implementation and preparation. Only an independent certification body can carry out the certification audit and provide the ISO 27001 certificate.

Is a GAP analysis wise in advance?

A GAP analysis is usually wise as it shows the starting position, priorities and realistic planning. If a recent and reliable analysis is already available, implementation can build on it.

Can Normity be used for ISMS?

Yes. Kynexis Information security can structure risks, demands, measures, actions, owners and evidence in Normity. An equivalent environment is also possible when it reliably supports ISMS.

Wouter Parent

An ISMS is successful when management can steer and employees can work with it. The certificate is a confirmation, not a final destination.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates