Kaizen Consulting0800 KAIZENBook a consultationBook a call
Home/Services/ISO Standards/ISO 27001 — Information Security
ISO 27001:2022 · INFORMATION SECURITY

ISO 27001 — security your clients can audit.

The information security standard enterprise clients and government buyers demand. We build your ISMS around your real systems and data flows — risk register, Annex A controls, Statement of Applicability — then take it through certification with a JAS-ANZ accredited body.

Fixed-price quotation16–20 weeks, brief to certificateOur platform Teammate is ISO 27001 certified
SPEC PLATE — AT A GLANCE
STANDARDISO 27001:2022
SCOPEInformation security management (ISMS)
TIMELINE16–20 weeks typical
CERTIFICATIONStage 1 + Stage 2, JAS-ANZ accredited body
CYCLEAnnual surveillance · 3-year recertification
PAIRS WITHISO 9001 — shared clauses, one management review
Quoted fixed-price after a thirty-minute scoping call
FIXED PRICEQUOTED · LOCKED
WHO IT SERVES

Built for companies whose deals stall at the security questionnaire.

USE-01
Closing enterprise and government deals

Procurement asks for 27001 before the contract conversation starts. Certification replaces the 300-row security questionnaire with one certificate.

USE-02
Standing up a real ISMS, not a policy pack

Bought-template policies fail Stage 1. We build the risk register, pick the Annex A controls that fit, and write the Statement of Applicability from decisions you actually made.

USE-03
Keeping the evidence trail alive

Access reviews, backup tests, incident drills — the ISMS calendar schedules each control's evidence so surveillance audits are routine, not panic.

CLAUSE REGISTER

What the standard asks. What we build.

Clauses 4–10 · the auditable core
CLAUSETHE STANDARD ASKS FORWHAT KAIZEN BUILDS WITH YOU
CL 4Context of the organisationISMS scope, interested-parties register and the issues log — systems, data flows and dependencies.
CL 5LeadershipInformation security policy, role assignments and accountabilities your directors can sign.
CL 6PlanningThe information security risk register, risk treatment plan and the Statement of Applicability.
CL 7SupportCompetency, awareness training, communication and controlled documents.
CL 8OperationOperational controls from Annex A — access, cryptography, suppliers, incidents, continuity.
CL 9Performance evaluationControl monitoring and measurement, the internal audit programme and management review.
CL 10ImprovementCorrective actions from incidents and findings — root cause to close-out, with the evidence trail.
SEQUENCE — HOW WE DELIVER IT
The full method →
WK 1
Scope & fixed quote
WK 2–3
Gap analysis
WK 3–11
System build
WK 11–16
Implement & train
WK 16–20
Certification audit
THE DEAL

What you get, what it costs, how long it takes.

DELIVERABLES
ISMS manual, risk register & treatment planStatement of Applicability — the Annex A controls that fitInternal audit + management review, run with your teamIncident response & access-review proceduresCertification audit support — we're in the room
INVESTMENT
Fixed price, quoted in writing

Scoped on a thirty-minute call. The quote covers everything on this page — no hourly surprises, no scope creep. Every line item is in the quote.

TIMELINE
16–20 weeks, brief to certificate

Confirmed in the quote and planned backwards from the certification audit date. Urgent timeline? Say so on the call — compression is a specialty.

Certificate valid 3 years with annual surveillance
REF — RELATED SPEC SHEETS
Full registry →
STD-9001ISO 9001 — QualitySTD-45001ISO 45001 — Health & SafetySTD-IMSIntegrated Management Systems
Q&A — ISO 27001

No — it's a management system that governs IT. Your technical team implements controls; the ISMS decides which ones, owns the risks and holds the evidence. We run the system side and work alongside your IT.

An independent, JAS-ANZ accredited certification body — never us. We build the system, prepare your team and support you through their Stage 1 and Stage 2 audits. That separation is what makes the certificate credible.

All new certifications are to ISO 27001:2022 — 93 Annex A controls in four themes. From 2013 it's a mapped transition, not a rebuild; we run it inside your surveillance cycle where possible.

NEXT STEP

Ready to get ISO 27001 under way?

A thirty-minute scoping call, then a fixed-price quote in writing — with the certification date planned from day one.

Book a consultation0800 KAIZEN (524 936) · hello@kaizenconsulting.co.nz