ISO 27001 consultants in South Africa
A real information security management system, current to the 2022 edition, with a Statement of Applicability that holds up.
ISO/IEC 27001:2022 is the standard for managing information security risk. We help you build a genuine ISMS: scope, risk assessment, a defensible Statement of Applicability across the Annex A controls, and the evidence to pass an accredited audit, so it stands up to real scrutiny from customers and auditors alike.
And because our iQuotient platform ships a current-edition ISMS module, we can run the SoA, information assets and control evidence live. The starting point, as always, is a gap audit.
What we do
- ISMS scope, context and information-security risk assessment.
- Statement of Applicability across the ISO/IEC 27001:2022 Annex A controls.
- Information assets, access control, supplier security and confidentiality evidence.
- Security incident, review and management-review workflows.
- Certification-body preparation, and a live ISMS in iQuotient if you want it.
Is this you?
Client or contract requirement
A customer or contract requires certified information security. You need an accredited 27001 certificate, not a logo.
Data-sensitive operations
You handle sensitive data and need defensible control of access, suppliers, incidents and confidentiality.
Maturing tech business
You have outgrown ad-hoc security and want a managed, auditable ISMS that scales.
Frequently asked questions about ISO 27001
What makes a 27001 certificate count?
Are you current to the 2022 edition?
Do we need the iQuotient platform for 27001?
How do we start?
Ready to start your ISO 27001 journey?
Contact us. We'll show you where you stand and the realistic, accredited path to certification.
