ISO 27001 Readiness
Build an ISMS that operates rather than a binder that satisfies - and arrive at Stage 1 with a real management system, not a document project.
What This Engagement Covers
ISO 27001 certifies a management system rather than a moment in time. The registrar is not looking for a policy set - they are looking for an ISMS that is defined, implemented, and operating, with a risk register that drove control selection and a Statement of Applicability that can be defended. We run readiness so that when your registrar conducts Stage 1, the ISMS exists and the Stage 2 evidence is already accumulating.
What This Means for Canadian Businesses
ISO 27001 is an international standard, and its geographic reach makes it the most common certification ask for Canadian companies operating internationally - particularly in financial services, government supply chains, and technology sectors where Canadian and international buyers both require it. Canadian federal and provincial government procurement increasingly references ISO 27001 or equivalent controls as a supplier requirement. The standard's control set (Annex A, ISO 27002:2022) maps well to Canadian privacy requirements, and the risk-based approach aligns with OSFI guidance for regulated financial institutions. Where SOC 2 evidence already exists, a substantial portion carries across to Annex A without duplication.
Domains & Controls We Assess
We evaluate every technical, operational, and administrative requirement against authoritative criteria.
Organizational Controls (A.5)
- A.5.1 - Policies for information security: defined, approved, and communicated
- A.5.2 - Information security roles and responsibilities assigned and documented
- A.5.9 - Inventory of information and associated assets maintained and owned
- A.5.15 - Access control policy governing physical and logical access decisions
- A.5.23 - Information security requirements for cloud services defined and managed
- A.5.30 - ICT readiness for business continuity planned and tested
People Controls (A.6)
- A.6.1 - Screening of candidates proportionate to role sensitivity and data access
- A.6.3 - Information security awareness, education, and training programme
- A.6.4 - Disciplinary process for information security policy violations
- A.6.5 - Responsibilities on change of employment or termination defined
- A.6.8 - Information security event reporting mechanisms available to workforce
Physical Controls (A.7)
- A.7.1 - Physical security perimeters protecting information processing facilities
- A.7.2 - Physical entry controls restricting access to authorised personnel
- A.7.4 - Physical security monitoring of sensitive areas
- A.7.8 - Equipment siting and protection from environmental threats
- A.7.14 - Secure disposal or re-use of equipment containing storage media
Technological Controls (A.8)
- A.8.2 - Privileged access rights managed and reviewed on a defined cycle
- A.8.5 - Secure authentication mechanisms for system and application access
- A.8.7 - Protection against malware across end-user and server environments
- A.8.8 - Management of technical vulnerabilities through timely remediation
- A.8.15 - Logging of activities, exceptions, and security events; log protection
- A.8.24 - Cryptography policy governing use of controls to protect information
- A.8.28 - Secure coding practices applied throughout the development lifecycle
Risk Management (Clauses 6 & 8)
- Clause 6.1.2 - Information security risk assessment process documented and repeatable
- Clause 6.1.3 - Statement of Applicability produced with justified inclusion/exclusion of controls
- Clause 8.2 - Risk assessment performed on a defined schedule or triggered by change
- Clause 8.3 - Risk treatment plan implemented and tracked to completion
ISMS Operations (Clauses 9 & 10)
- Clause 9.1 - Monitoring, measurement, analysis, and evaluation of ISMS performance
- Clause 9.2 - Internal audit programme planned and executed at defined intervals
- Clause 9.3 - Management review of ISMS conducted at planned intervals
- Clause 10.1 - Continual improvement: nonconformities identified, corrected, and recurrence prevented
Engagement Deliverables
Everything you need to prove control operating effectiveness to your auditors and enterprise clients.
ISMS Scope Statement and Boundary Documentation
Information Security Risk Assessment and Risk Register
Statement of Applicability (all Annex A controls)
Gap Assessment Report Mapped to ISO 27002:2022
Mandatory Clause Documentation (Internal Audit, Management Review)
Audit-Ready Policy and Procedure Templates
Trusted by Growing Businesses
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Common Questions
ISO 27001 certifies an information security management system against an international standard; SOC 2 is an AICPA attestation on controls at a point in time or over a period. ISO 27001 is the more common ask outside North America. The control overlap between Annex A and the SOC 2 criteria is substantial, so running both together costs far less than running them sequentially.
Yes, Clause 9.2 requires it, and Clause 9.3 requires a management review. Both must have occurred before Stage 2. Registrars look for genuine internal audit evidence - not a document that describes what an audit found but a programme that actually ran. We conduct the internal audit as part of readiness so it is real rather than retrospective.
It records which Annex A controls apply to your ISMS and why. Controls excluded without a defensible justification are one of the most common Stage 1 findings. An SoA that says "not applicable" without explanation is a red flag to a registrar and to buyers who review it as part of due diligence.
Often Scoped Together
Ready for Your ISO 27001 Readiness Assessment?
Speak directly with our senior Canadian compliance team. We establish your exact scope, quote a fixed flat-rate price, and deliver a definitive timeline.