I will prepare your iso 27001 documents and audit evidence
Linux, VMware and ISO 27001 Infrastructure Engineer
About this Gig
Your auditor asked for evidence and you do not have it. Or a client sent a security questionnaire, or an insurer wants proof of an ISMS. Often the controls already exist - what is missing is the documentation that proves it.
I have taken an organisation through ISO 27001:2022 certification end to end, Stage 1 and Stage 2, with every non-conformity closed in the corrective action window.
WHAT YOU GET
- Gap assessment against all Annex A controls, ranked by risk and effort
- Information Security Policy, Statement of Applicability, Risk Assessment and Treatment Plan
- Full ISMS pack: 20+ sub-policies, ROPA, risk register, internal audit checklist
- Evidence log mapped to controls, so an auditor can see what you actually do
Note: this is information security and compliance work, not legal advice.
WHY ME
CISA certified and a former appointed Data Protection Officer. Six years running production infrastructure, so the controls I write are ones you can operate - not templates that collapse at Stage 2 because nobody can evidence them.
Tell me your scope, your deadline, and whether an audit is booked. If your position is stronger than you think, I will say so.
Field of law:
Privacy
Target Country:
United Arab Emirates
Language:
English
Legal consulting Gigs are not screened
Please note that there is no screening process for this service. We recommend that you message the freelancer and check all necessary details before placing your order. Pro freelancers in this category have gone through a vetting process. You can find more details here.
My Portfolio
FAQ
Can you guarantee we will pass certification?
No, and nobody honestly can - the certification body decides. What I can do is make sure your documentation, risk assessment and evidence are complete and defensible before they arrive. On the certification I led, every non-conformity was closed within the corrective action window.
Are these just templates?
No. Templates are why organisations fail Stage 2 - an auditor asks how a control works in practice and nobody can answer. I write policies against your actual systems and scope, which is why I ask questions before starting rather than sending a generic pack.
Do you provide legal advice on data protection law?
No. I am not a lawyer. I work on information security management, ISO 27001 implementation and audit readiness, and I have served as an appointed Data Protection Officer. For legal opinions on liability or contracts, you need qualified counsel in your jurisdiction.
Which package do we need?
Start with the gap assessment if you do not know where you stand - it tells you. Take Core Policy Set if you have nothing documented yet. Choose Full ISMS Pack if you have an audit booked and need the complete evidence base.
Will you need access to our systems or data?
Usually no. Most of this is built from interviews, your asset inventory and a description of your environment. If I need to see a configuration to evidence a control, I will ask for a screenshot rather than access, and I sign an NDA on request.
What are your working hours and how do you communicate?
I am in Dubai, GST timezone. I reply within a few hours during my day and always within 24 hours. Everything stays in Fiverr messages so there is a written record, and I send a progress update at each stage rather than going quiet until delivery.
What format are the documents, and can we edit them?
Editable Word and Excel files, plus PDF copies. You own them outright and can amend them as the business changes - which you will need to do, because an ISMS is a living system rather than a one-time delivery.

