Skip to content
RTResilience TechGOVERNANCE · RISK · COMPLIANCE
Menu
All consulting services

An ISO 27001 aligned security operating model

Cyber Security Process Consulting

Security comes from building processes, not from buying products. We establish an ISO 27001 aligned management system and make every flow work in practice, from incident response to access management.

Objective

Build a process-led rather than product-led security operating model that is measurable and sustainable.

Scope

ISMS and ISO 27001 implementation

Scope definition, asset inventory, risk assessment, policy and procedure sets, Annex A control selection, internal audit and continual improvement.

Risk management and compliance

Threat modelling, third-party and supplier risk, and the compliance work required by data protection law and sector regulation.

Data security

Data classification, DLP policies, encryption and key management, logging and retention policies.

SecOps and incident management

Incident classification and response playbooks, SOC processes, alert lifecycle and table-top exercises.

Identity and access management

IAM and PAM process design: lifecycle, least privilege, access approval flows and periodic review.

Secure software development

Secure SDLC: secure coding policies, SAST and DAST processes, dependency management and dev-sec-ops rhythms.

Key deliverables

  • ISMS document set
  • RACI responsibility matrix
  • Incident response playbooks
  • IAM/PAM access flows
  • Secure SDLC controls
  • Data and DLP policies
  • KPI and SLA dashboards focused on MTTA/MTTR

How an engagement runs

All four services follow the same path. We do not design before measuring, and we do not finish before handing over.

01

Assessment

  • Maturity measurement of the current state
  • Stakeholder interviews and document review
  • Gap analysis and prioritisation

02

Design

  • Target operating model
  • Process, policy and RACI set
  • Measurement framework: SLA, KPI, OKR

03

Implementation

  • A roadmap that starts with quick wins
  • Working alongside your teams, with training
  • Dashboards and reporting put in place

04

Handover

  • Process ownership moves inside the organisation
  • Internal audit and improvement rhythm
  • Left working without the consultant

Related product

SentinelCore

Find vulnerabilities in your code without sending it anywhere

Details →

Let's discuss what this means for your organisation

Tell us where you stand today and we will work out together where to begin. A first conversation, no commitment.