
A working ISMS
How do you build an ISMS that demonstrably works?
Kynexis Information Security guides you from scope and risk analysis to policies, measures, evidence, internal audit and management assessment. The result is an ISMS that is in line with daily practice and can be prepared for an independent certification audit.
- ISO 27001 documents grow, but ownership and daily execution remain behind.
- Implementation is with one specialist, while processes and measures are intended to work organisation-wide.
- Teams do not know enough what evidence is needed and how checks are carried out.
- You want to certify without building an ISMS paper that stops after the audit.
What are the risks? Without workable implementation, ISO 27001 will become a documentation project. This takes a lot of time, while management and employees cannot steer and work with it.
Our promise of service
ISO 27001 guidance connecting documentation and practice
Kynexis Information Security helps you implement ISO 27001 at a pace and form that suits your organisation, with clear owners, useful evidence and permanent security.
- Workable scope and risk approach
- Measures with ownership and proof
- Preparation for internal and certification audit
ISO 27001 implementation support
What is ISO 27001 guidance?
Kynexis Information Security guides you from scope and risk analysis to policies, measures, evidence, internal audit and management assessment. The result is an ISMS that is in line with daily practice and can be prepared for an independent certification audit.
When does this service fit?
A management system that helps the organisation to steer
This guidance fits when the ambition is clear and the organisation wants to actually organise or improve the ISMS. An ISO 27001 GAP analysis can determine the starting position in advance. The implementation then focuses on coherence, implementation and evidence.
Implementation areas
All building blocks of ISO 27001 in workable coherence
Existing processes and documents are used as much as possible. Only what is necessary for control, operation and detection is added.
Context and Scope
Identifying organisational context, stakeholders, processes, locations and boundaries of ISMS.
Risks and treatment
Practically organise methodology, risk analysis, treatment plan and acceptance criteria.
Policy and responsibilities
Policy, roles, objectives and decision making are linked to the organisation.
Annex A and Application
Select, support and define measures in the Applicability Declaration.
Operation and evidence
Organise checks, registrations, suppliers' agreements and supporting documents in a cyclical manner.
Evaluation and improvement
Perform internal audit, management review, deviations and corrective actions.
Your result
A demonstrable ISMS ready for independent review
You have a coherent management system with clear owners, current risks and demonstrable execution. Kynexis Information Security prepares the organisation for content; the certification audit and the certificate shall remain with an independent certification body.
- Clear ISM scope and governance
- Current risk analysis and treatment plan
- Declaration of Applicability
- Operational controls and structured evidence
- Internal audit, management review and improvement cycle
How we work
Phased building with clear owners
- 01
Start and GAP
To determine ambition, scope, starting position and project design.
- 02
Design
Develop a risk approach, policy, roles, measures and evidence structure.
- 03
Implement
Perform processes, involve employees and build evidence of operation.
- 04
Keys and preparations
Perform internal audit and management review and finish open points.
Preparation for certification
A logical route with independent roles
Kynexis Information Security guides implementation and preparation. The certification body shall then independently carry out the certification audit.
ISO 27001 GAP Analysis
To determine what's already in place and what's still needed.
View this phase →ISMS device
Bringing together risks, policies, roles and measures.
ISO 27001 implementation support
Building functioning and evidence in practice.
Fit for this implementation phaseInternal audit
Objective assessment and completion of improvement points.
Independent audit
Certification by an appropriate body.
Discuss your current situation, certification target and the support needed to make it work demonstrably.
Plan a guidance interview →Frequently Asked Questions
Practical answers on ISO 27001 implementation support
What does ISO 27001 include?
The guidance includes the design and operation of ISMS: Scope, governance, risk analysis, risk management, policies, measures, evidence, internal audit, management review and continuous improvement.
Can Kynexis issue the ISO 27001 certificate?
No. Kynexis Information Security guides implementation and preparation. Only an independent certification body can carry out the certification audit and provide the ISO 27001 certificate.
Is a GAP analysis wise in advance?
A GAP analysis is usually wise as it shows the starting position, priorities and realistic planning. If a recent and reliable analysis is already available, implementation can build on it.
Can Normity be used for ISMS?
Yes. Kynexis Information security can structure risks, demands, measures, actions, owners and evidence in Normity. An equivalent environment is also possible when it reliably supports ISMS.

An ISMS is successful when management can steer and employees can work with it. The certificate is a confirmation, not a final destination.