ISO 27001 consultant — an ISMS that certifies the first time.
A working information security management system, not a binder of policies: risk assessment, Statement of Applicability, Annex A controls implemented in your AWS account, internal audit and certification-body liaison. CISA · AWS Pro · 16+ years.
Establish, implement, certify, maintain
Establish the ISMS
- Scope, context, risk assessment and treatment plan
- Statement of Applicability
- Policies aligned to Annex A
Implement Annex A in AWS
- Access control, cryptography, logging, operations security as real AWS controls
- Asset and supplier management
- Secure development and change control
Audit & certify
- Internal audit and management review
- Certification-body Stage 1 / Stage 2 liaison
- Nonconformity remediation
Maintain certification
- Continual improvement and surveillance-audit readiness
- Evidence automation
- Retainer option
Track record
Questions buyers ask
What is an ISMS?
An information security management system — the risk-driven set of policies, controls and processes ISO 27001 certifies. I build one that reflects how your AWS environment actually works.
How long to certification?
Typically a few months depending on size and starting maturity: establish the ISMS, implement controls, run an internal audit, then Stage 1 and Stage 2 with the certification body.
Do you implement Annex A controls in AWS?
Yes — access control, crypto, logging and operations controls become real configurations (IAM, KMS, CloudTrail, Config), with evidence, not just written policy.
Do you liaise with the certification body?
Yes. I prepare the environment and evidence and support you through the Stage 1 and Stage 2 audits.
An ISMS your auditor certifies the first time.
Free 30-minute call — tell me your scope, timeline and current state.