Skip to content
HEM Bilişim
All services

Compliance

ISO 27001 implementation and audit readiness

We build the information security management system, make the controls operational and prepare you for the certification audit.

  • ISO/IEC 27001

Getting an ISO 27001 certificate and operating an information security management system are two different jobs. Implementations that define controls on paper and stop there run into trouble at the first surveillance audit. We tie the controls to the organisation's daily work.

Scope

01

Scope definition and asset inventory

02

Risk assessment methodology and risk treatment plan

03

Policies, procedures and the Statement of Applicability

04

Implementing Annex A controls and assigning owners

05

Internal audit, management review and certification readiness

What we deliver

A working information security management system

Risk register and risk treatment plan

Statement of Applicability and document set

Internal audit report and corrective action list

How we proceed

The process for this service

1

Scope and asset inventory

What is in scope and which assets are being protected.

2

Risk assessment

A method is chosen, risks are scored, and the treatment plan gets owners.

3

Putting controls into operation

Annex A controls are tied to daily work and assigned owners.

4

Internal audit and readiness

Findings are closed before the audit and management review is held.

Questions about this service

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation