Security Assurance · GRC · Secure AutomationRemote delivery for growing technology businesses
ISO/IEC 27001

Prepare for ISO 27001 with controls that can survive evidence review.

Tech Turn helps technology companies move from unclear requirements and scattered evidence to a structured ISMS, prioritised remediation plan and certification-ready operating model.

Service boundary

Where Tech Turn fits.

The consultancy supports the client before and between formal certification audits.

Gap Assessment

Determine current-state gaps, control maturity and evidence quality against the agreed scope.

Readiness & Implementation

Build or repair the ISMS, risk process, SoA, policies, ownership and evidence structure.

Internal Audit & Follow-up

Perform or coordinate internal audit work where independence is preserved, then verify corrective actions.

Typical readiness scope.

The exact scope depends on the organisation, certification boundary and Statement of Applicability.

  • ISMS scope and context
  • Leadership and information-security policy
  • Risk assessment and risk treatment
  • Statement of Applicability support
  • Security objectives and metrics
  • Documented information and evidence structure
  • Competence and awareness
  • Operational control ownership
  • Access and privileged access
  • Supplier security
  • Incident management
  • Vulnerability and patch governance
  • Backup and resilience
  • Logging and monitoring
  • Change management
  • Internal audit and management review

Certification is a separate decision.

Tech Turn does not issue an ISO certificate.

Establish the ISMS

Define the scope, risks, controls, processes and records.

Complete internal activities

Run the risk process, internal audit, management review and corrective actions.

Stage 1

The certification body reviews readiness and documented ISMS foundations.

Stage 2

The certification body evaluates implementation and operating effectiveness.

Certification decision

The certification body completes its decision process and issues the certificate when requirements are met.

Surveillance and recertification

The organisation maintains the ISMS through surveillance and the subsequent recertification cycle.

Entry point

Useful first deliverable.

If you do not know how far you are from readiness, start with a gap assessment rather than buying a large implementation project.

ISO 27001 Gap Assessment

Typical outputs include scope assumptions, clauses and controls reviewed, evidence sampled, conforming and partially conforming areas, gaps, risk priorities, corrective actions and a readiness conclusion.