Cargando
Preparando la información solicitada…
Cargando
Preparando la información solicitada…
Complete ISMS implementation. From gap assessment to certification audit preparation. We prepare your organization — certification is issued by an independent accredited body.

"Certification is not the final goal — it is the evidence that your management system works."Fernando Arrieta — Lead Auditor ISO/IEC 27001
More and more contracts require ISO 27001 as a prerequisite. Certification is increasingly a documented requirement in international supply chains.
Fintech, healthcare, government, and insurance companies need to demonstrate security controls to regulators and supervisory bodies.
If you process personal, financial, or health data, ISO 27001 provides the framework to protect it and prove it.
Evaluation of the current state vs. ISO 27001 requirements. Identifies what exists, what is missing, and where to start.
Mapping of information assets, threats, vulnerabilities, and required controls based on your context.
Design of policies, procedures, controls, and roles. Operational documentation that is used, not archived.
Pre-certification verification: we detect findings and correct them before the external audit.
Complete preparation: audit simulation, findings closure, and documentation ready for the independent certification body.
Detailed map of what you comply with and what is missing, prioritized by risk and effort.
Policies, procedures, risk matrix, Statement of Applicability (SoA), and operational records.
Selected Annex A controls with owners, deadlines, and verification criteria.
Complete verification before certification. Corrected findings and documented evidence.
Audit simulation, management review, and non-conformity closure prior to the external audit.
Post-implementation support to maintain and improve the ISMS. Surveillance and the certification cycle are the responsibility of the certification body.
It depends on the size and maturity of the organization. On average, full implementation takes between 4 and 8 months. Organizations with mature processes can achieve it in 3 months. The preliminary diagnosis is delivered in 72 hours, allowing you to plan the timeline.
The cost varies depending on the scope, number of locations, and complexity of the organization. The consulting investment covers diagnosis, implementation, and preparation. The certification audit is a separate service contracted directly with the accredited certification body.
The Information Security Management System (ISMS) is the framework that defines how your organization protects its information assets. It includes policies, roles, access controls, incident management, and continuous improvement. ISO 27001 is the international standard certifying that your ISMS meets globally recognized requirements.
No. Many organizations start from scratch. The initial assessment maps the current state, and the readiness process covers diagnosis, implementation, and preparation. The certification audit is a separate step managed by an independent accredited body.
Yes. ISO 27001 is an internationally recognized standard worldwide. Certification is issued by an independent accredited certification body and has global validity. Fernando Arrieta provides readiness preparation — the certification decision is the exclusive responsibility of the accredited body.
The 2022 version includes 93 controls in Annex A, organized into 4 categories: organizational, people, physical, and technological. Not all are mandatory: they are applied based on your organization's risk analysis.
If your organization is evaluating ISO 27001 readiness, this is the channel to discuss scope and viability. All inquiries are handled under confidentiality.
The consulting and implementation services described on this site are provided independently. Certification audits and decisions are the exclusive responsibility of accredited certification bodies. In accordance with ISO/IEC 17021-1 §5.2, impartiality restrictions and cooling-off periods apply.