ISO/IEC 27001:2022 sets requirements for an information security management system. The standard is about establishing, implementing, maintaining and improving the governance of information security across the organisation. Certification documents that the system exists, is used and is improved, assessed by an independent auditor.
Many organisations meet the requirement from the outside. Customers ask for it in tenders, owners expect it, and regulatory requirements such as NIS2 and sector rules point the same way. Others start from within, because the security work has grown too large to run without a system. The challenge is usually the same: documentation exists in fragments, responsibility is unclear, and nobody can show as a whole what is actually in place.
Berigo helps build a management system fitted to the organisation, one that withstands an audit because it is genuinely used. The result should be an operational management system, not a document library.
Who this is for
- Organisations meeting ISO/IEC 27001 requirements in tenders, customer agreements or owner dialogue.
- Organisations in scope of NIS2 or other sector requirements that need systematic security governance.
- Organisations that already have a management system but do not know whether it is certification-ready.
- Organisations that have grown quickly, where security work has become dependent on individuals.
- Groups that need one management system across legal entities, countries and locations.
What Berigo can deliver
- Organisational context, interested parties and their requirements.
- Scope for the management system, bounded and justified.
- Leadership commitment, information security policy and security objectives.
- Roles, responsibilities and authority, including ownership of risks and controls.
- Risk assessment methodology, the assessments themselves and a risk treatment plan.
- Control selection and a Statement of Applicability with justification for each control.
- Governance documentation and operational procedures that suit how the organisation works.
- Competence and awareness work for leadership, key roles and staff.
- Control follow-up, evidence collection and incident handling.
- Supplier management, including contractual requirements and follow-up of critical suppliers.
- Measurement, reporting to management, internal audit and management review.
- Nonconformity handling, corrective action and the improvement process.
- Preparation for the certification audit, and support through stage 1 and stage 2.
Four starting points we can work from
- Build a new management system from the ground up.
- Improve an existing management system that is not working as intended.
- Make an existing management system certification-ready.
- Establish one management system across several jurisdictions, or integrate it with ISO/IEC 42001, ISO 22301 or ISO/IEC 27701.
What you gain
- A management system leadership actually steers by, with objectives that are followed up.
- An overview of risk, controls and responsibility, gathered rather than scattered.
- Documentation that shows what has been done, ready for auditors, customers and supervisory authorities.
- A shorter path through security questions in tenders and customer agreements.
- A foundation for further work on other standards and regulatory requirements.
TrustAlign in the work
TrustAlign is Berigo's own portal for governance, risk, compliance and audit support. It is used as the working surface through implementation and onwards into operation, so that requirements, work and evidence sit together instead of being scattered across spreadsheets and shared folders.
- Frameworks and requirements, with compliance status per framework.
- Risk register with risk assessment and follow-up of treatment.
- Control register with status, owners and deadlines.
- Statement of Applicability, with justification per control.
- Policies and governance documents.
- Audit programme, audit plans and the running of audits.
- Findings classified as nonconformity, observation or opportunity for improvement, with root cause, corrective action and verified closure.
- Incidents, vulnerabilities, assets and suppliers.
- Evidence and documentation attached to what it belongs to.
- Management review built on the audit programme.
- Reports and exports of risks, controls, findings, incidents, policies, suppliers and vulnerabilities.
- Norwegian and English interface, a separate organisation per client, roles for administrator, manager and viewer, two-factor sign-in and an audit log.
TrustAlign can be used as a standalone portal, and can by agreement and technical clarification be connected to relevant document and data sources. The portal by itself provides neither certification nor regulatory compliance. It structures the work that has to be done, and makes it verifiable.
Who does what
Berigo is an adviser and implementation partner. The certification audit is carried out by an independent certification body that you choose yourselves. We issue no certificates, we do not influence the auditor's judgement, and we do not guarantee a particular outcome. We prepare the organisation as well as we can, and support you through the audit and the work that follows.