Cybersecurity · 2025 · 08 months per client

ISO 27001 Information Security Management Implementation

"100% certification success rate with zero major non-conformities at Stage 2."

Role

GRC Analyst & Project Manager

Industry

Cybersecurity, Tech, SaaS, Legal, Early-Stage Tech, EdTech

Tools

ISMS templates, Risk registers, Statement of Applicability, Audit trackers

Overview

Led and coordinated end-to-end ISO 27001 consulting and implementation projects across multiple client organisations. The work focused on establishing compliant ISMS, ensuring audit readiness, and supporting clients through successful certification audits, including managing documentation, training, timelines and confidentiality in high-pressure audit environments.

Challenges

  • Limited internal security expertise and awareness.
  • Fragmented documentation and processes.
  • Concurrent project timelines with tight audit deadlines.
  • Coordinating diverse stakeholders such as executives, IT/DevOps, legal and external auditors.
  • Typical implementation timelines of 6 to 18 months compressed into 9 to 12.

Approach & Solution

  • Defined ISMS scope and tailored implementation roadmaps per client.
  • Authored full documentation suites: policies, procedures, SOPs, risk assessments, SoA and trackers.
  • Designed standardised templates and evidence-collection tools to accelerate readiness.
  • Delivered targeted security awareness and ISO 27001 training across technical and non-technical staff.
  • Managed stakeholder alignment, auditor scheduling, query resolution and Stage 1 & 2 audit support.

Results

  • All supported projects achieved successful ISO 27001 certification with zero major non-conformities at Stage 2.
  • Consistently positive auditor feedback on documentation quality, evidence completeness and overall coordination.
  • Internal security culture improved markedly through structured training and communication.