What you read, and what you do not read
This document outlines the requirements of the standard, our working method, our deliverables, and the points checked by the certifying body auditor. It contains no client names, no testimonials, and no quantified results: our confidentiality commitments prohibit this. The volumes below are counted in our management system.
What ISO 27001 really requires
Information security policy
Establish a clear policy that defines security objectives and responsibilities.
Risk assessment
Identify and assess information security risks to implement appropriate measures.
Security controls
Implement technical and organisational controls to protect information.
Training and awareness
Train staff on security practices and raise awareness of risks.
Continuous improvement
Establish processes to monitor, review, and improve the ISMS regularly.
How we conduct the mission
Preliminary analysis
Carry out an initial diagnosis to assess the current state of information security.
Planning
Develop a detailed action plan for implementing the standard's requirements.
Implementation
Assist the company in applying security controls and policies.
Internal audit
Conduct internal audits to verify compliance and effectiveness of the ISMS.
Preparation for external audit
Prepare the company for the certification audit by a third-party body.
What you receive
- Information security assessment
- Action plan for implementation
- ISMS documentation
- Internal audit report
- Staff training
- Preparation for certification audit
Who is involved in your case
Security consultant
Supports the implementation of the standard's requirements.
Trainer
Facilitates awareness and training sessions on security.
Internal auditor
Conduct audits to assess the compliance of the ISMS.
What the certifying body checks
- Compliance of security policies
- Effectiveness of technical controls
- Staff awareness
- Security incident management
- Continuous improvement of the ISMS
The difficulties we encounter most often
Underestimating risks+
Lack of management commitment+
Insufficient training+
Non-compliance with requirements+
Cover part of the cost
Depending on your status and project, part of the cost may be covered by Moroccan support mechanisms — special training contracts, sector funds, competitiveness support programmes. Eligibility is verified on a case-by-case basis: we check it with you before any commitment.
What is expected of us regarding ISO 27001
What are the main benefits of ISO 27001 certification?+
What does a certification audit involve?+
What is the duration of a compliance project?+
What are the costs associated with implementing the standard?+
How to maintain compliance after certification?+
Your ISO 27001 project
A 30-minute exchange is sufficient to identify your gap against the framework and inform you what the approach entails for your organisation.
Request a diagnosisPoursuivre la lecture
ISO 37301 — conformité (compliance)
Lire →IATF 16949 — industrie automobile
Lire →ISO 45001 — santé et sécurité au travail
Lire →Pour voir ces principes appliqués à un cas entièrement calculé, consultez les études de cas chiffrées.
