Home / Knowledge centre / Case studies / Case study

ISO 27001:2022 certification for a SaaS provider

Client

[Client name]

Sector

Software as a service

Service

ISO 27001:2022

Duration

[Engagement length]

The challenge

Where the customer started

[To be supplied: the customer’s situation, what was at stake and why they came to iSecurify]

The outcome

What changed

[Result to be confirmed]

[Result to be confirmed]

[Result to be confirmed]

How the engagement ran

The steps below are the standard approach for this service. Replace them with the specifics of the engagement.

01

Gap assessment

We compare current practice with the standard and report what is missing.

02

Scope definition

We agree which locations, teams, products and systems the ISMS will cover.

03

Risk assessment and treatment

Risks are identified, rated and assigned a treatment with an owner.

04

Statement of Applicability

Each Annex A control is marked as applicable or not, with justification.

05

Policies and procedures

Documents are written or updated to match how you work.

06

Annex A controls

Applicable controls from the 93 across four themes are implemented and evidenced.

[Customer quote about this engagement to be supplied]

[Customer name]
[Title, Company]

Draft note: sample outline to show the layout. Client name, figures and quote are to be supplied, with the customer’s written permission.

Ready to talk about your security and compliance goals?

Tell us where you are today. We will suggest a sensible next step, with no obligation.

info@isecurify.co