Company details
Menu
WFH Labs / ISO 27001 technical preparation

Prepare the systems and evidence behind your ISO 27001 work.

ISO 27001 is a standard for an information security management system. We help with the technical part: checking that the safeguards selected for your organisation are implemented and that you can show how they operate.

Where we can help

  • How selected controls apply to the systems within your audit scope.
  • Access reviews, system maintenance, logging and recovery arrangements.
  • Differences between the written process and actual working practice.
  • Records your team needs to maintain and explain during a review.

What you receive

  • A review of the IT safeguards selected for your ISO 27001 scope.
  • A list of differences between documented procedures and actual system settings or working practices.
  • An evidence checklist and agreed technical tasks to prepare for the audit.

Help implementing these changes can be included in the agreed scope.

What is ISO 27001?

ISO/IEC 27001 is a standard for an information security management system, often shortened to ISMS. This is how an organisation identifies security risks, chooses safeguards, assigns responsibilities and reviews whether the arrangements work.

Certification assesses the management system within its defined scope. Buying a tool or writing policies does not establish conformity. Technical preparation helps connect the selected safeguards to what happens in your systems.

ISO: ISO/IEC 27001 overview ↗

What does useful audit evidence look like?

Evidence is a record that supports a specific statement. Examples include a dated access review, a restore-test result or an approved change with its checks. It should show what was examined, by whom, when, and what happened next.

We check the safeguards and records relevant to your agreed scope. If a procedure says one thing and the system does another, the next step is to resolve that difference and record the result.

Example: your backup procedure says recovery is tested. A successful backup-job screenshot shows a copy was made; a restore-test record helps show it can be used.

Questions about this work

Do you issue ISO 27001 certificates?

No. Certification is performed by a certification body. WFH helps prepare the technical systems and evidence within your agreed scope.

Can you work with our auditor or ISMS consultant?

Yes. We can use the agreed scope, selected safeguards and findings as inputs, clarify the technical tasks and coordinate responsibilities with the people already involved.

Can we start before all documentation is complete?

Yes. A focused review can establish current working practices and identify the changes needed. The documents should describe arrangements your team can actually follow.

How the work begins

Share your agreed scope, requirements and available system information. We identify the people who need to contribute and confirm the work, responsibilities and expected result before starting.

Key terms

Read ISO’s explanation of ISO/IEC 27001 ↗

Next step / Start with your situation

You do not need to know the technical term.

Tell us what is happening, what it affects and when you need help. We’ll discuss whether we can help and what a useful first piece of work would be.