ISO 27001 Compliance Preparation ASAP
Budget / Salary₹12,500–37,500
TypeFreelance project
LocationRemote
Posted1 hour ago
Our organisation is at the very first steps of ISO 27001 implementation and we have an external certification audit on the horizon. I need your help right now to put a solid compliance framework in place, beginning with two critical areas:
• Documentation review & creation – build or refine the full document set (ISMS manual, policies, procedures, Statement of Applicability, control evidence templates, etc.) so every clause and Annex A control is clearly mapped and traceable.
• Risk assessment & management – run a comprehensive risk assessment, populate a risk register, prioritise treatments, and deliver an actionable risk treatment plan that aligns with business objectives.
I already have a high-level plan but no detailed artefacts, so you will be shaping the baseline from scratch, coaching me through each requirement, and ensuring everything produced will stand up to auditor scrutiny. Speed is key: I need initial drafts within days and a complete, audit-ready package as soon as realistically possible.
Please outline how you normally tackle gap analysis, which industry-recognised tools or templates you prefer (e.g. ISO 27005 methodology, risk matrix spreadsheets, asset inventory software, etc.), and the timeline you can commit to for each milestone—draft documents, risk workshop, final review.
Acceptance criteria
• All mandatory ISO 27001:2022 documents delivered, internally consistent, and version-controlled.
• Risk register and treatment plan approved by management.
• Clear cross-reference matrix showing evidence against every Annex A control.
• Guidance notes for us to maintain and continuously improve the ISMS post-engagement.
If you can start immediately and hit these targets, let’s move forward today.
• Documentation review & creation – build or refine the full document set (ISMS manual, policies, procedures, Statement of Applicability, control evidence templates, etc.) so every clause and Annex A control is clearly mapped and traceable.
• Risk assessment & management – run a comprehensive risk assessment, populate a risk register, prioritise treatments, and deliver an actionable risk treatment plan that aligns with business objectives.
I already have a high-level plan but no detailed artefacts, so you will be shaping the baseline from scratch, coaching me through each requirement, and ensuring everything produced will stand up to auditor scrutiny. Speed is key: I need initial drafts within days and a complete, audit-ready package as soon as realistically possible.
Please outline how you normally tackle gap analysis, which industry-recognised tools or templates you prefer (e.g. ISO 27005 methodology, risk matrix spreadsheets, asset inventory software, etc.), and the timeline you can commit to for each milestone—draft documents, risk workshop, final review.
Acceptance criteria
• All mandatory ISO 27001:2022 documents delivered, internally consistent, and version-controlled.
• Risk register and treatment plan approved by management.
• Clear cross-reference matrix showing evidence against every Annex A control.
• Guidance notes for us to maintain and continuously improve the ISMS post-engagement.
If you can start immediately and hit these targets, let’s move forward today.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.