SIA IA Standards
Map IA controls into the same treatment plan and evidence set.
Home / Services / Information Security and ISO 27001
Specialised practice · ISMS
The data you must protect mostly belongs to someone else. Our ISO 27001 consultants design, implement and prepare your information security management system (ISMS) for certification, built once so that one system of controls and evidence answers each authority that will examine it. Most engagements begin under a client contract, a board decision, or a regulator such as SIA, ADHICS, DESC ISR or the ADGM Cyber Risk Management Framework (CRMF).
One system, every examiner
A single management system can provide the governance, control evidence and audit trail required by certification bodies, regulators and demanding clients.
One governed evidence base for risk, controls, operation and assurance.
Map IA controls into the same treatment plan and evidence set.
Use the ISMS structure to organise healthcare-specific obligations and audit evidence.
Evidence ISR requirements through controlled documents, ownership and operating records.
Connect board oversight, cyber risk and incident readiness to the ISMS rhythm.
Use a recognised framework as the governed basis for cyber-risk management.
Answer security questionnaires and contractual controls from the same evidence base.
Delivery pathway
The sequence is designed to make the system defensible before an external examiner sees it.
Confirm entities, sites, systems, authorities and certification boundaries.
OutputGap and scope decision
Classify assets, assess threats and decide treatment priorities.
OutputRisk and asset registers
Build the SoA, policies, ownership and practical control design.
OutputSoA and treatment plan
Run controls, awareness, internal audit and management review.
OutputOperating evidence cycle
Prepare for Stage 1, Stage 2 and relevant regulatory scrutiny.
OutputAudit support and close-out
Evidence package
The proposal identifies exactly which artefacts apply to your scope.
Gap assessment, scope statement, policy, roles and decision rights.
Asset register, classification, risk criteria and assessed risk register.
Statement of Applicability, treatment plan and mapped obligations.
Policies, procedures, control records, awareness and competence evidence.
Internal audit, management review and Stage 1/Stage 2 support plan.
Is this the right service?
Clear responsibilities
The proposal names the Engagement Lead and separates consultancy, operation and independent certification.
Scope, facilitate, design, coach, internally audit where appropriately separated, and quality-review the work.
Named Engagement LeadMake risk decisions, assign owners, operate controls and maintain evidence as part of everyday management.
Management accountabilityConduct Stage 1 and Stage 2 audits and decide whether certification requirements are met.
Independent decisionQuestions buyers ask
It depends on scope, existing maturity and how quickly decisions are made, typically several months for a focused scope and longer for complex or multi-entity organisations. A timeline quoted in days leaves no room for a risk assessment, an operating cycle or an internal audit, all of which certification bodies expect to see.
Proposals differ in what sits behind the certificate. When comparing them, weigh accreditation of the certification body, who performs the work, the depth of the risk assessment, quality review by a practitioner not involved in delivery, and post-certification support, not price alone. A certificate from an unaccredited body may not satisfy procurement due diligence, whatever it cost.
Yes. The ISMS is a governance system and does not replace technical operations. We define the structure, controls and evidence; your technical teams and providers operate within it.
It depends on who is asking for assurance: UAE regulators and government buyers reference ISO 27001, while some international clients ask for SOC 2. The control work overlaps substantially, so we help you sequence rather than duplicate.
Eleven governance control areas that decide whether an ISMS survives contact with an auditor. Scored honestly, it tells you which areas would hold under pressure.
Twenty minutesCandidly scored
Explore representative anonymised assignments across government, aviation, healthcare, retail and real estate, manufacturing, and maritime services.
Tell us which regulator or client is asking, and by when. We aim to respond within two business days.
Related: Business Continuity · Integrated Management Systems · Governance, Risk & Assurance