Ongoing ISO 27001 ISMS Support
Budget / SalaryHourly project
TypeFreelance project
LocationRemote
Posted2 hours ago
We already run an ISO 27001:2022-certified ISMS, but the day-to-day work needed to keep it sharp has outgrown our in-house capacity. I’d like a security professional to partner with us long-term and take ownership of three core activities:
• Risk assessment & treatment – Keep the risk register current, re-score risks when our environment changes, and refine treatment plans so the Statement of Applicability always reflects reality.
• Gap-analysis internal audits – Plan and conduct internal audits focused on finding control gaps before the external auditors do, then deliver concise reports and corrective-action tracking.
• Policy development & maintenance – Review every policy in the ISMS library, update wording to match ISO 27001:2022 terminology, and draft new material when business processes evolve.
All required controls are already implemented, so the emphasis is on maintaining evidence rather than rolling out new technology. I’ll give you full access to existing documentation, past audit findings, and our risk tool (Excel-based for now). You will work remotely, meet with key process owners, and deliver updated artefacts in GDrive on an agreed schedule.
Acceptance criteria
1. Updated risk register and SoA published quarterly.
2. Gap-analysis audit report—with findings, priorities and corrective actions—delivered within five working days of each audit.
3. Policy set reviewed end-to-end once per year, with change log and version control maintained.
If you are comfortable navigating ISO 27001:2022, Annex A, and the PDCA cycle, this should be straightforward work delivered consistently every month.
• Risk assessment & treatment – Keep the risk register current, re-score risks when our environment changes, and refine treatment plans so the Statement of Applicability always reflects reality.
• Gap-analysis internal audits – Plan and conduct internal audits focused on finding control gaps before the external auditors do, then deliver concise reports and corrective-action tracking.
• Policy development & maintenance – Review every policy in the ISMS library, update wording to match ISO 27001:2022 terminology, and draft new material when business processes evolve.
All required controls are already implemented, so the emphasis is on maintaining evidence rather than rolling out new technology. I’ll give you full access to existing documentation, past audit findings, and our risk tool (Excel-based for now). You will work remotely, meet with key process owners, and deliver updated artefacts in GDrive on an agreed schedule.
Acceptance criteria
1. Updated risk register and SoA published quarterly.
2. Gap-analysis audit report—with findings, priorities and corrective actions—delivered within five working days of each audit.
3. Policy set reviewed end-to-end once per year, with change log and version control maintained.
If you are comfortable navigating ISO 27001:2022, Annex A, and the PDCA cycle, this should be straightforward work delivered consistently every month.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.