ISO 27001
Policy and Documentation Creation
ISO 27001:2022 names thirteen documents an ISMS must hold, and an auditor will ask for every one of them. The difficulty is not producing thirteen files; it is producing thirteen that describe what the organisation does. A generic policy set is recognisable to any auditor on sight and signals that the management system was bought rather than built.
Methodology
- 01
Context
Establish the organisational context, the ISMS scope and the processes the documentation has to describe.
- 02
Document Set Definition
Determine which of the mandatory documents apply, and which additional procedures and records the scope calls for.
- 03
Contextual Drafting
Draft ISMS policies, procedures and records tailored to the organisation rather than issued from a template.
- 04
Process Alignment
Map each document to the business process it governs, and to the owner who runs that process.
- 05
Review and Approval
Take the set through review with its owners and formal management approval.
- 06
Version Control
Place the approved set under version control so the audit trail exists from the first issue.
Approach to testing
- Requirement — what does the applicable standard, regulation or framework require?
- Control — what control has the organisation established?
- Implementation — how is the control actually implemented?
- Evidence — what evidence demonstrates that the control operates?
- Risk — what happens if the control is ineffective or absent?
- Action — what needs to be changed?
- Validation — has the corrective action actually addressed the issue?
Types of assessment
Black-Box
Assessment begins with limited organisational information, to provide an independent perspective of the governance environment.
Grey-Box
Selected organisational documentation, process information and evidence are provided for structured assessment.
White-Box
Full documentation, evidence, stakeholder and process access is provided for detailed control validation.
Hybrid
Combines independent assessment techniques with detailed evidence and stakeholder validation.
Frameworks and standards
- ISO/IEC 27001:2022
- Clauses 4-10, which define the documented information the management system must hold.
- ISO/IEC 27002:2022
- Control guidance the procedures are written against.
- CSS Security Governance Toolkit
- Document structure, approval workflow and version control.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
CSS Security Governance Toolkit
Document set structure, review and approval records, version history.
CSS ISO 27001 Toolkit
The baseline the tailored set is drafted from, rather than issued as.
PlyoGRC
Where appropriate, documents and their approval records are held as controlled records rather than files on a share.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
Mandatory documents
- Scope of the ISMS
- Information Security Policy
- Risk Assessment and Risk Treatment Methodology
- Statement of Applicability
- Risk Treatment Plan
- Information Security Objectives
- Evidence of Competence
- Monitoring and Measurement Results
- Internal Audit Programme and Results
- Results of Management Review
- Results of Corrective Actions
- Logs of Activities of Top Management
- Logs of Nonconformities and Corrective Actions
Supporting procedures
- Access control and identity management
- Incident management and reporting
- Business continuity and recovery
- Supplier and third-party management
- Change and configuration management
- Asset management and classification
Document control
- Named owner per document
- Approval record and date
- Version history
- Review cycle defined and scheduled
- Distribution and accessibility to the people who must follow it
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Framework Mapping Agent — maps requirements and controls across applicable frameworks.
Policy Analysis Agent — identifies potential missing, inconsistent or outdated requirements.
Evidence Analysis Agent — associates evidence with applicable controls and identifies evidence gaps.
Risk Analysis Agent — identifies recurring risk themes and potential control weaknesses.
Blind-Spot Detection Agent — looks for issues that may not be immediately visible through conventional checklist assessment.
Executive Reporting Agent — helps transform detailed assessment information into concise management reporting.
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
Tailored, not templated
Documents are drafted against the organisation's own context and processes. A generic policy set is recognisable to any auditor and tells them the management system was bought rather than built.
Mapped to processes that run
Each document is tied to the business process it governs and the owner who runs it. A policy owned by nobody is a document, not a control.
Audit-ready from issue
Version control, approval records and review cycles are in place from the first issue, not assembled in the weeks before an audit.
Operating control, not documentation only
Evidence is validated across five stages: Designed — is it appropriately designed? Implemented — has it been implemented? Operating — is it actually performed? Evidenced — can operation be shown? Effective — is it achieving its goal?
Human-in-the-loop AI assistance
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
What you receive
A working management system, not a folder of documents
The target state is that owners know what they must do, management knows what decisions are pending, and evidence exists to demonstrate that controls operate. Outputs are grouped by who uses them.
Executive layer
Scope, risk posture, roadmap, management decisions, KPI/KRI, readiness summary
GRC layer
Risk register, Statement of Applicability, policies, procedures, ownership, evidence map, action tracker
Assurance layer
Internal audit, findings, CAPA, management review, certification-readiness assessment
Operational layer
Control records, recurring reviews, awareness, supplier / access / incident / continuity evidence as applicable
Governance cadence established
- Monthly
- Risk / action review, evidence status, control exceptions, material incidents
- Quarterly
- Risk trend, supplier / control reviews, KPI/KRI, management action tracking
- Annual
- Internal audit programme, management review, ISMS objectives, risk refresh, improvement plan
For this engagement specifically
- Control owners
- IT teams
- Security teams
- Compliance teams
- Process owners
- Auditors
- Key risks
- Significant gaps
- Business impact
- Priority actions
- Ownership
- Target timelines
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.