An ISO 27001 aligned security operating model
Cyber Security Process Consulting
Security comes from building processes, not from buying products. We establish an ISO 27001 aligned management system and make every flow work in practice, from incident response to access management.
Objective
Build a process-led rather than product-led security operating model that is measurable and sustainable.
Scope
ISMS and ISO 27001 implementation
Scope definition, asset inventory, risk assessment, policy and procedure sets, Annex A control selection, internal audit and continual improvement.
Risk management and compliance
Threat modelling, third-party and supplier risk, and the compliance work required by data protection law and sector regulation.
Data security
Data classification, DLP policies, encryption and key management, logging and retention policies.
SecOps and incident management
Incident classification and response playbooks, SOC processes, alert lifecycle and table-top exercises.
Identity and access management
IAM and PAM process design: lifecycle, least privilege, access approval flows and periodic review.
Secure software development
Secure SDLC: secure coding policies, SAST and DAST processes, dependency management and dev-sec-ops rhythms.
Key deliverables
- ISMS document set
- RACI responsibility matrix
- Incident response playbooks
- IAM/PAM access flows
- Secure SDLC controls
- Data and DLP policies
- KPI and SLA dashboards focused on MTTA/MTTR
How an engagement runs
All four services follow the same path. We do not design before measuring, and we do not finish before handing over.
01
Assessment
- Maturity measurement of the current state
- Stakeholder interviews and document review
- Gap analysis and prioritisation
02
Design
- Target operating model
- Process, policy and RACI set
- Measurement framework: SLA, KPI, OKR
03
Implementation
- A roadmap that starts with quick wins
- Working alongside your teams, with training
- Dashboards and reporting put in place
04
Handover
- Process ownership moves inside the organisation
- Internal audit and improvement rhythm
- Left working without the consultant
Related product
SentinelCore
Find vulnerabilities in your code without sending it anywhere
Let's discuss what this means for your organisation
Tell us where you stand today and we will work out together where to begin. A first conversation, no commitment.