Discover
Understand business context, interested parties, scope and objectives.
Practical, risk-based information-security consulting designed around your organization.
JULA can support the organization from initial readiness through implementation and preparation for certification. The certification decision itself remains with an independent certification body.
Understand business context, interested parties, scope and objectives.
Compare current practices and documentation with ISO/IEC 27001 requirements.
Identify, analyze and prioritize information-security risks.
Develop governance, policies, procedures, objectives and the risk-treatment approach.
Put controls into operation and establish responsibilities and evidence.
Train employees and embed security responsibilities into everyday work.
Test implementation and identify corrective actions before external certification.
Give leadership visibility of performance, risks, actions and improvement.
Prepare evidence, teams and processes for the independent certification audit.
Maintain, monitor and improve the ISMS after implementation.