EmberKat

ISO 27001 technical consulting

ISO 27001 Technical Consulting

EmberKat helps teams align ISO 27001 control implementation, technical evidence, ownership and audit findings with how the environment operates in practice.

Discuss the scope
Typical durationUsually 2–4 weeks
Starting priceFrom €12,500 excl. VAT
Commercial basisWritten scope and proposal

Service definition

Make the audit story hold up technically

The engagement makes the technical side of the ISMS inspectable: which systems are in scope, how controls operate, who owns them and what evidence supports the claim.

Scope

Work included in the scope

  1. 01

    Technical scope and asset-boundary review

  2. 02

    Control implementation and operating-evidence assessment

  3. 03

    Identity, access, logging, resilience and supplier-control review

  4. 04

    Secure development and vulnerability-management evidence review

  5. 05

    Audit-finding root-cause and remediation analysis

  6. 06

    Ownership, evidence cadence and closure criteria

Client problems

Use this service when

  1. 01

    The policy set is ahead of the technical implementation.

  2. 02

    Evidence is collected manually before every audit or customer review.

  3. 03

    Control owners cannot explain how a requirement works in the environment.

  4. 04

    Audit findings are accepted on paper but return during retest.

Deliverables

Documents and decisions provided

  1. 01

    Technical control and evidence map

  2. 02

    System, owner and evidence-gap register

  3. 03

    Prioritised ISO 27001 remediation backlog

  4. 04

    Finding closure criteria and verification plan

  5. 05

    Audit-readiness summary for technical leadership

From the glossary

remediation
Actually fixing what an assessment found — as opposed to recording it.
ISO 27001
An international standard for how an organisation runs its information security — the management side, not the product.
The full glossary

Related engagement

Cybersecurity & Compliance Engineering

The broader security engineering model for controls, ownership and review evidence.

View engagement