optimizarIA Services Explore the interactive desktop

Gobierno de seguridad · Cybersecurity

ISO/IEC 27001:2022 implementation

We take your organisation from where it stands today to an Information Security Management System ready to be audited and certified.

Standard
ISO/IEC 27001:2022 and Annex A
Duration
8 to 14 months depending on scope
Team
Certified Senior Lead Implementer
Output
ISMS ready for certification audit

The problem

ISO 27001 certification stopped being an ornament: more and more corporate clients and public tenders demand it as a condition to contract. The 2022 version reorganised the Annex A controls into four themes and added eleven new ones, so an implementation based on the old edition no longer works.

What it includes

Análisis de brechas

Contraste del estado actual contra cada requisito de la norma y cada control del Anexo A, con el porcentaje de cumplimiento real por cláusula.

Alcance y contexto

Definición del alcance del SGSI, las partes interesadas y sus requisitos, que es donde se decide cuánto costará todo lo demás.

Gestión de riesgos

Metodología de evaluación y tratamiento, inventario de activos, riesgos valorados con dueños asignados y Declaración de Aplicabilidad.

Cuerpo documental

Política del SGSI, procedimientos obligatorios, registros y evidencia, redactados para tu operación y no copiados de una plantilla.

Implementación de controles

Acompañamiento técnico en los controles del Anexo A que exigen trabajo real: accesos, criptografía, respaldo, registro, desarrollo seguro y proveedores.

Concientización y competencias

Formación al personal y a la alta dirección, con la evidencia que el auditor pedirá.

Auditoría interna y revisión

Ejecución de la auditoría interna, tratamiento de no conformidades y revisión por la dirección antes de convocar al ente certificador.

Acompañamiento en certificación

Preparación de la etapa 1 y la etapa 2, y apoyo durante la auditoría del organismo certificador.

How we work

  1. 01
    Diagnóstico
    Brecha contra la norma, alcance propuesto y estimación de esfuerzo.
  2. 02
    Diseño
    Metodología de riesgos, política, roles y plan de tratamiento aprobados por la dirección.
  3. 03
    Implementación
    Despliegue de controles y generación de evidencia, con seguimiento quincenal.
  4. 04
    Verification
    Auditoría interna, no conformidades y revisión por la dirección.
  5. 05
    Certification
    Acompañamiento en las etapas 1 y 2 con el organismo certificador.

Deliverables

DocumentLength
Manual del SGSI
Alcance, política, roles y procesos.
included
Declaración de Aplicabilidad
Control por control, con justificación.
included
Matriz de riesgos
Valorada, con dueños y plan de tratamiento.
included
Cuerpo documental
Procedimientos y registros obligatorios.
included
Informe de auditoría interna
Con no conformidades y acciones.
included
Note

Certification is issued by an independent body, not by us. Our job is to leave the system in a condition to pass: we prepare, accompany and answer during the audit, but the verdict comes from an accredited third party, which is precisely what gives the certificate its value.

Other services in this area

Cybersecurity posture assessmentDetailed analysis of the real state of your security: vulnerabilities, threats and compliance level, with a clear view of the risks and how to mitigate them.Ethical HackingOffensive security analysis on the target you define, run under the OWASP Testing Guide and classified with OWASP Top 10, CWE and CVSS 3.1.Web application and API penetration testingWe attack your application the way a real adversary would, with written authorization and scope, and hand you every finding with a reproducible proof of concept.Mobile application audit (APK)We decompile, instrument and attack your Android application to find what a store review would never see.Red Team and Purple TeamFull adversarial assessment and collaborative work with your defensive team, mapped to MITRE ATT&CK, to strengthen the defences where they actually give way.APT-style exercisesSimulation of advanced persistent threats to measure how your organisation holds up against the most sophisticated scenarios, in white box or black box.Simulated phishing and awarenessWe measure how your people respond, not your software: controlled social engineering campaigns that end in training built on the real cases from the exercise.Digital forensic analysisFast, precise answers once something has happened: what got in, through where, when and what it took, with evidence valid for legal proceedings.Incident response and digital forensicsWhen something has already happened, we contain it, investigate what occurred and leave you with what you need so it does not happen again.Building your CSIRTWe design, implement and train your organisation's computer security incident response team, so the capability stays in house.Security Operation CenterCreation and rollout of a centralised unit that monitors, detects, responds to and mitigates threats in real time, on your premises and with your trained staff.Digital security monitoringConstant supervision of all your digital assets, with proactive defence against environmental threats and reports that can actually be read.Server hardeningComprehensive hardening of your servers: optimised configuration, patch management and periodic audits to close the door before anyone tries it.Cloud hardening: GCP, AWS and AzureWe review your entire account against the CIS benchmark, fix whatever you authorize and show you the before and after with a posture score.Cloud services: migration and architectureMigration, architecture design, implementation, resource optimisation and account management on AWS, Google Cloud and Azure, with security built in from day one.Connectivity and networksWe connect your organisation to the world securely: structured cabling, network security and orderly workstations.Information security planA plan of your own, aligned with your business objectives: assessed risks, policies written to measure and a security culture that reaches every employee.Cybersecurity roadmapA strategic plan for the short, medium and long term that sets priorities, defines concrete actions and allocates resources, aligned with business objectives.vCISO: your security chief, without the payrollAn information security officer with committed hours each month, answering for your company's governance, risk and compliance before the board and before your clients.ISO/IEC 27001:2022 internal auditWe audit your Information Security Management System with the same rigour the certification body will apply, so nothing surprises you on the real audit day.Law 21.719 and Law 21.595 complianceWe get your company ready for the Chilean personal data law before the regulator arrives, with documentation checked against the official text.Security toolingLicensing and rollout of the most widely used offensive and defensive tools on the market, with the technical support to make them actually pay off.Technology equipmentComputers, servers and specialised tooling for physical hacking, with architecture advice included.

All practice areas

Want to hire this service?

Write to us at contacto@optimizaria.com and we reply the same business day.

Explore the interactive desktop