I will create your iso 27001 isms documentation, risk assessment and policies
About this gig
Preparing for ISO 27001 certification and not sure what the auditor will ask for? I've been on both sides of the table: 7 years auditing IT controls at PwC, and today I run the ISO 27001, ISO 27701 and PCI DSS certification programme of a payments company, whose latest ISO 27001 audit closed with no major non-conformities.
I work with ISO/IEC 27001:2022 and write documents that fit your company's size, not a 300-page template nobody reads.
What you get:
- Gap analysis of clauses 4-10 and the 93 Annex A controls
- - ISMS scope and information security policy
- - Risk assessment methodology and risk register
- - Statement of Applicability (SoA)
- - Annex A policies and procedures (Premium)
- - 90-day roadmap to your Stage 1 audit (Premium)
- - Editable Word and Excel files
How it works:
- You answer a short questionnaire about your company, systems and current controls
- 2. I prepare the documents and we review them together
- 3. You get the final files, ready for your auditor
Message me before ordering if you want to talk about scope.
Get to know Michel D
Technology Risk GRC Specialist
- FromBrazil
- Member sinceSep 2026
- Avg. response time1 hour
Languages
English, Portuguese
My Portfolio
FAQ
Can you certify us?
Certificates are issued by accredited certification bodies. My job is to get your ISMS documented and ready, so the audit goes smoothly.
Which version of the standard do you use?
ISO/IEC 27001:2022, including the new Annex A structure (93 controls in 4 themes). If you are still on the 2013 version, I can help with the transition.
Can you also cover ISO 27701, SOC 2 or GDPR?
Yes. I run ISO 27701 alongside ISO 27001 in my current role. Message me before ordering and I'll send a custom offer.
Do you need access to our systems?
No. I work from your answers, your existing documents and a short call if needed. Please don't send passwords or production data.

