Become certification-ready for ISO/IEC 27001

An information security management system that is used in practice, documented as you go and able to withstand a certification audit. Gap assessment, advisory support or full implementation.

ISO/IEC 27001:2022 sets requirements for an information security management system. The standard is about establishing, implementing, maintaining and improving the governance of information security across the organisation. Certification documents that the system exists, is used and is improved, assessed by an independent auditor.

Many organisations meet the requirement from the outside. Customers ask for it in tenders, owners expect it, and regulatory requirements such as NIS2 and sector rules point the same way. Others start from within, because the security work has grown too large to run without a system. The challenge is usually the same: documentation exists in fragments, responsibility is unclear, and nobody can show as a whole what is actually in place.

Berigo helps build a management system fitted to the organisation, one that withstands an audit because it is genuinely used. The result should be an operational management system, not a document library.

Who this is for

  • Organisations meeting ISO/IEC 27001 requirements in tenders, customer agreements or owner dialogue.
  • Organisations in scope of NIS2 or other sector requirements that need systematic security governance.
  • Organisations that already have a management system but do not know whether it is certification-ready.
  • Organisations that have grown quickly, where security work has become dependent on individuals.
  • Groups that need one management system across legal entities, countries and locations.

What Berigo can deliver

  • Organisational context, interested parties and their requirements.
  • Scope for the management system, bounded and justified.
  • Leadership commitment, information security policy and security objectives.
  • Roles, responsibilities and authority, including ownership of risks and controls.
  • Risk assessment methodology, the assessments themselves and a risk treatment plan.
  • Control selection and a Statement of Applicability with justification for each control.
  • Governance documentation and operational procedures that suit how the organisation works.
  • Competence and awareness work for leadership, key roles and staff.
  • Control follow-up, evidence collection and incident handling.
  • Supplier management, including contractual requirements and follow-up of critical suppliers.
  • Measurement, reporting to management, internal audit and management review.
  • Nonconformity handling, corrective action and the improvement process.
  • Preparation for the certification audit, and support through stage 1 and stage 2.

Four starting points we can work from

  • Build a new management system from the ground up.
  • Improve an existing management system that is not working as intended.
  • Make an existing management system certification-ready.
  • Establish one management system across several jurisdictions, or integrate it with ISO/IEC 42001, ISO 22301 or ISO/IEC 27701.

What you gain

  • A management system leadership actually steers by, with objectives that are followed up.
  • An overview of risk, controls and responsibility, gathered rather than scattered.
  • Documentation that shows what has been done, ready for auditors, customers and supervisory authorities.
  • A shorter path through security questions in tenders and customer agreements.
  • A foundation for further work on other standards and regulatory requirements.

TrustAlign in the work

TrustAlign is Berigo's own portal for governance, risk, compliance and audit support. It is used as the working surface through implementation and onwards into operation, so that requirements, work and evidence sit together instead of being scattered across spreadsheets and shared folders.

  • Frameworks and requirements, with compliance status per framework.
  • Risk register with risk assessment and follow-up of treatment.
  • Control register with status, owners and deadlines.
  • Statement of Applicability, with justification per control.
  • Policies and governance documents.
  • Audit programme, audit plans and the running of audits.
  • Findings classified as nonconformity, observation or opportunity for improvement, with root cause, corrective action and verified closure.
  • Incidents, vulnerabilities, assets and suppliers.
  • Evidence and documentation attached to what it belongs to.
  • Management review built on the audit programme.
  • Reports and exports of risks, controls, findings, incidents, policies, suppliers and vulnerabilities.
  • Norwegian and English interface, a separate organisation per client, roles for administrator, manager and viewer, two-factor sign-in and an audit log.

TrustAlign can be used as a standalone portal, and can by agreement and technical clarification be connected to relevant document and data sources. The portal by itself provides neither certification nor regulatory compliance. It structures the work that has to be done, and makes it verifiable.

Who does what

Berigo is an adviser and implementation partner. The certification audit is carried out by an independent certification body that you choose yourselves. We issue no certificates, we do not influence the auditor's judgement, and we do not guarantee a particular outcome. We prepare the organisation as well as we can, and support you through the audit and the work that follows.

Choose your delivery level

Three ways into the same goal. You can start with one and move on to another.

Gap assessment

A structured assessment of where you stand today.

The gap assessment is for organisations that want to know what is missing before committing to anything more. We assess current governance and practice against the requirements of the standard, and deliver a picture you can act on. The assessment stands on its own, and commits you to nothing further.

Scope and price are set after an initial clarification.

What it covers

  • Scope clarification, so the assessment addresses the right part of the organisation
  • Review of existing governance and governance documentation
  • Interviews with relevant roles, from leadership to those doing the work
  • Assessment against the requirements of the standard
  • Assessment of operational practice, meaning what is actually done
  • Identification of gaps and weaknesses
  • Maturity assessment
  • Prioritisation of measures by risk and effort
  • A recommended road map
  • An executive summary

What you are left with

  • A gap assessment report
  • A prioritised action plan
  • An overview of critical gaps
  • A recommended implementation sequence
  • A basis for deciding and planning the next phase

What you contribute

  • Access to the documentation and systems to be assessed
  • Time from the roles to be interviewed
  • A contact person who can clarify along the way
Get in touch

Advisory support

You own and run the work. We stand alongside as your expert support.

Advisory support is for organisations that want to own and run the implementation themselves, but need expert assistance along the way. You keep project management and ownership of the documents. Berigo acts as expert adviser, quality assurer and sounding board.

Scope and price are set after an initial clarification.

What it covers

  • Ongoing advice throughout implementation
  • Expert quality assurance of choices and solutions
  • Review of documents you have prepared
  • Support to project management without taking it over
  • Support for risk assessments and methodology
  • Support for control design
  • Support for documentation and structure
  • Support for building internal competence
  • Periodic status meetings at an agreed cadence
  • Support when nonconformities and obstacles appear
  • Certification readiness support

What you are left with

  • A management system you have built yourselves, with expert backing
  • Internal competence that stays in the organisation
  • Documentation you know from the inside, because you wrote it
  • Confidence that the choices will withstand an audit

What you contribute

  • Project management and progress
  • Resources to prepare documentation and implement measures
  • Decisions that require management authority
  • Ownership of the management system
Get in touch

Full implementation

We lead and carry out the bulk of the work, together with you.

Full implementation is for organisations that want Berigo to lead and carry out the bulk of the work. We take project management, build the management system and bring it to a certification-ready state. The client still owns the management system, and some things can only be done by the organisation itself.

Scope and price are set after an initial clarification.

What it covers

  • Project management and a detailed project plan
  • Establishment of the management system, with structure and processes
  • Document development, both governance and operational documents
  • Process development fitted to how you work
  • Risk assessments and control mapping
  • Implementation support for process owners, risk owners and control owners
  • Training and awareness
  • Internal audit, organised with the necessary independence
  • Preparation and running of the management review
  • Certification readiness, including a readiness assessment
  • Support during the certification audit
  • Follow-up of findings and nonconformities after the audit

What you are left with

  • An operational management system in day-to-day use
  • Documentation fitted to the organisation rather than taken from a generic template
  • A completed internal audit and management review
  • An organisation prepared for stage 1 and stage 2
  • A plan for continued operation and improvement

What you contribute

  • Leadership commitment, with genuine priority
  • Relevant resources and time from key roles
  • The necessary decisions, taken in time
  • Ownership of the management system, including after the project ends
  • Implementation of organisational and technical measures in your own organisation
  • Adherence to the processes once they are established
Get in touch

Download the service description

Enter your email address and you get the PDF straight away.

Your address is used to send you this PDF. You are not signed up for marketing, and you can ask for deletion at any time.

Proven Executive Outcomes

M&A

Uncovered critical IT vulnerabilities in a major tech acquisition, securing deal value.

NIS2

Guided a Nordic critical infrastructure provider from limited visibility to board-approved NIS2 compliance in 6 months.