Freelance · remoteISO 27001 · ISMSCISA · AWS Pro

ISO 27001 consultant — an ISMS that certifies the first time.

A working information security management system, not a binder of policies: risk assessment, Statement of Applicability, Annex A controls implemented in your AWS account, internal audit and certification-body liaison. CISA · AWS Pro · 16+ years.

Book a 30-min Strategy SessionEmail me
What I do

Establish, implement, certify, maintain

Establish the ISMS

  • Scope, context, risk assessment and treatment plan
  • Statement of Applicability
  • Policies aligned to Annex A

Implement Annex A in AWS

  • Access control, cryptography, logging, operations security as real AWS controls
  • Asset and supplier management
  • Secure development and change control

Audit & certify

  • Internal audit and management review
  • Certification-body Stage 1 / Stage 2 liaison
  • Nonconformity remediation

Maintain certification

  • Continual improvement and surveillance-audit readiness
  • Evidence automation
  • Retainer option
Proof

Track record

0major nonconformities target
Annex Acontrols implemented, not just documented
AWSISMS grounded in the real account
ISO 27001ISMSAnnex AStatement of Applicabilityrisk assessmentinternal auditcertificationAWSCISA
FAQ

Questions buyers ask

What is an ISMS?

An information security management system — the risk-driven set of policies, controls and processes ISO 27001 certifies. I build one that reflects how your AWS environment actually works.

How long to certification?

Typically a few months depending on size and starting maturity: establish the ISMS, implement controls, run an internal audit, then Stage 1 and Stage 2 with the certification body.

Do you implement Annex A controls in AWS?

Yes — access control, crypto, logging and operations controls become real configurations (IAM, KMS, CloudTrail, Config), with evidence, not just written policy.

Do you liaise with the certification body?

Yes. I prepare the environment and evidence and support you through the Stage 1 and Stage 2 audits.

An ISMS your auditor certifies the first time.

Free 30-minute call — tell me your scope, timeline and current state.

Book a callSOC 2 consulting →