i-Prot

Frameworks · ISO/IEC 27001:2022

ISO/IEC 27001: certify your information security management system.

We prepare and support your organization to certify ISO/IEC 27001:2022 — with an ISMS that stays valid between surveillance audits.

diagram · frameworks · iso/iec 27001:2022

Who it applies to

ISO/IEC 27001 applies to any organization that manages sensitive information and needs to demonstrate that it protects it. It’s especially relevant when certification is a commercial or contractual requirement.

What the framework requires

The standard requires establishing, maintaining and improving a risk-based Information Security Management System (ISMS), together with the applicable controls from Annex A.

Clauses 4–10

Context, leadership, planning, support, operation, evaluation and improvement.

Risk management

Risk assessment and treatment as the core of the system.

Annex A · 93 controls

Organizational, people, physical and technological.

Statement of applicability

The SoA justifies which controls apply and why.

Risks of not acting

  • Being excluded from tenders and contracts that require a valid certification.
  • Managing security without a risk-based framework or formal evidence.
  • Facing audits with recurring findings and last-minute remediation.
  • Losing traceability between controls, risks and evidence.

The i-Prot proposal

We design and implement the ISMS, define the risk assessment and the statement of applicability, and prepare the organization for the certification audit. All integrated into the CGF governance cycle, so the certification holds over time.

How we work with this framework

Assessment and gap analysis

Gaps against the clauses and Annex A of 27001:2022.

Risk assessment and SoA

Risk methodology, treatment plan and statement of applicability.

Controls implementation

Annex A controls, policies and procedures with evidence.

Internal audit and review

Internal audit, management review and closure of findings.

Certification and upkeep

Support in the certification audit and continuous operation.

Deliverables

  • Gap analysis
  • Implementation plan
  • Controls matrix
  • System documentation
  • Evidence
  • Internal audit
  • Management review
  • Roadmap

How it connects with CGF

CGF uses ISO/IEC 27001 as a source of requirements. This framework mainly covers the Design, Implement, Operate & measure, and Improve stages of the cycle.

See the CGF methodology →

Complyze and ISO/IEC 27001

Complyze centralizes the 93 Annex A controls, their evidence and compliance status, and keeps progress by clause visible. Frameworks are the natural entry point to the platform.

Frequently asked questions

Ready to certify ISO/IEC 27001?

Tell us your context and we’ll propose a path to certification tailored to your organization.

By submitting you accept our privacy policy.

By submitting you accept the privacy policy and the processing of your data in order to be contacted.