ISO
We build the ISMS with you, starting from scope and the risk assessment. A first system and a multi-site system use the same engagement: we agree the sites, the shared controls, and the site-specific risks before we start. The Statement of Applicability, policies, and evidence index follow from those decisions, so the documents agree with each other. Before the Stage 1 audit we run an internal audit and a management review, because the auditor asks for both.
Engagement brief
Fixed scope
AccountableYour named owner
ResponsibleA Truvara practitioner
Drafts and citesCASK
Phases
We confirm scope and timing after a first call.
When teams call us
A large customer made ISO/IEC 27001 a contract condition
Tenders list the certificate as a requirement and you keep missing out
Someone started an ISMS last year and the documents stopped matching
You have a SOC 2 report and customers outside the US want ISO
What you receive
Drag the divider. On the left, where the work usually starts. On the right, the files you receive.
What you receive
The files from this engagement
Gap assessment
Implementation
Before the engagement
What we usually find on day one
Whatever was saved last. Scope, risk, and evidence still disagree.
What it works against
CASK maps every requirement to evidence in the workspace, so scoping starts from what already exists and what is missing.
Key areas covered
How it runs
One sequence, from the records you already have to the outcome in your hands.
Set the scope
Agrees with leadership which sites, teams, and systems the ISMS covers, and records why.
Assess risk
Runs the risk workshop and sets likelihood, impact, and treatment with each owner.
Write the Statement of Applicability and policies
Decides which Annex A controls apply and edits policies to match how your teams work.
Collect evidence and rehearse the audit
Follows up with control owners on missing evidence, then runs the internal audit, chairs the management review, and presents the readiness findings.
What we need from you
Questions