ISO 27001 gap analysis
We compare the current state with the standard and identify priorities, owners and the sequence of corrective actions.
- ISMS scope
- Context and interested parties
- Existing documentation review
ISO/IEC 27001:2022 implementation and audit
We design and organise an ISMS: from gap and risk analysis, through documentation and safeguards, to a readiness audit before ISO/IEC 27001:2022 certification.
Implementation scope
We do not begin with templates. We first understand the organisation’s context, processes, assets, dependencies and legal or contractual obligations.
We compare the current state with the standard and identify priorities, owners and the sequence of corrective actions.
We design policies, roles, registers and procedures that support actual operations rather than documentation created only for an audit.
We connect ISMS requirements with access control, backups, incident handling, suppliers, business continuity, DevOps and ITSM.
We verify system operation, implementation evidence and nonconformities before an independent certification audit.
Engagement stages
We agree the scope and pace after reviewing organisational size, processes, locations and the maturity of existing safeguards.
We define the ISMS scope, organisational context, processes, assets, interested parties, and legal and contractual requirements. We then compare the current state with ISO/IEC 27001:2022 and prioritise the required actions.
We identify threats and vulnerabilities, assess risks to information and processes, and select appropriate treatment options and safeguards. The results become an implementation plan with task owners, deadlines and performance indicators.
We design and launch policies, procedures, roles, registers, and organisational and technical safeguards. We train responsible personnel and collect evidence that the ISMS operates effectively in practice.
We assess ISMS conformity and effectiveness, identify nonconformities and observations, and prepare corrective actions. We support the management review and prepare the organisation for the certification audit.
Engagement outcome
The deliverables are tailored to the agreed project stage, the organisation’s size and the defined ISMS scope.
An assessment against ISO/IEC 27001:2022, including findings, evidence, priorities and recommended actions.
A structured risk assessment with acceptance criteria, owners, planned safeguards and implementation deadlines.
Policies, procedures, roles, registers, objectives, metrics and a Statement of Applicability aligned with the organisation’s actual processes.
Internal-audit results, corrective actions, required evidence and preparation for management review and the certification audit.
Business outcomes
Decisions about safeguards are based on risk, accountability and measurable objectives rather than individual incidents.
Structured evidence, roles and processes make it easier to meet contractual and tender requirements.
An ISMS can provide a common organisational foundation for information security, cyber resilience and data protection.
Frequently asked questions
It is an international standard specifying requirements for an Information Security Management System. It covers risk management, roles, objectives, process oversight and continual improvement of information protection.
Certification itself is voluntary, although it may be required by a contract, tender or group policy. An organisation may implement the standard without seeking certification.
An independent certification body issues the certificate after a successful audit. PAT-IT prepares the ISMS and organisation for that assessment but does not issue certificates.
Timing depends on the ISMS scope, number of processes and locations, maturity of safeguards and team availability. We prepare a realistic schedule after the gap analysis.
It can provide a structured foundation for information security and risk management. It does not replace an individual analysis of legal obligations under NIS2, Polish KSC legislation or GDPR.
An Information Security Management System (ISMS) is a structured framework of policies, processes, roles, responsibilities and safeguards used to manage information security risks. It encompasses establishing, implementing, maintaining and continually improving the protection of information, taking account of confidentiality, integrity and availability. It is not a single document or merely a set of IT solutions — it covers people, processes and technology.
Related areas
Entity self-identification, gap analysis, risk management and incident reporting processes.
Learn more →Data process mapping, controller and DPO duties, and personal data breach handling.
Learn more →Read the official description of the current standard on the ISO website.
Learn more →Contact us for a free 30-minute initial consultation.
Book a consultation ↗