Compliance

ISO 27001, with ISO365

A full Information Security Management System, built inside your own Microsoft 365 environment and run by people on a monthly rhythm until you are certified, and after. Delivered with ISO365, who specialise in ISO 27001 implementation and internal audit, while we implement the technical controls underneath it.

Somebody has asked you for ISO 27001

Usually a tender, or a customer large enough that their procurement team sets the terms. Occasionally a regulator, or a board that has read something. Either way it arrives with a date attached, as a requirement somebody else has set.

The common answer is a consultant, a folder of documents written to pass an audit, and a system that stops being maintained once the certificate is on the wall. It works once. The surveillance audit twelve months later is where it comes apart. By then the auditor is no longer reading the policies. They are asking for the year of evidence that the system operated: risk reviews held, treatments completed, corrective actions closed, a management review with minutes.

The alternative is a management system that keeps operating after the certificate arrives, built with the people who own the risks and the people who run the controls in the same room from the first workshop.

Six months, and then it keeps running

A defined pathway with audits at fixed points. The typical shape is below: build the system, embed it, certify, then maintain it so the next audit is not a project of its own.

  1. Months one and two

    Build. The gap analysis workshop tailors the policies to how you actually operate and populates the registers with real tasks. A full risk assessment follows. Your ISMS hub is built in your own SharePoint, with the policies and registers created inside it, and risk treatment starts.

  2. Months three and four

    Embed. Risk treatment continues and the registers are reviewed and updated on the monthly rhythm, so they have a history before an auditor reads them. Staff training and awareness runs. The Stage 1 audit, which reviews the documentation and your readiness, closes this stretch.

  3. Months five and six

    Certify. Risk treatment activities are finalised, ISO365 conducts the internal audit, the management review meeting is held, and the Stage 2 audit follows, which tests whether the system operates the way the documentation says it does.

  4. Ongoing

    Maintain. Monthly reviews of risk, performance and improvements. Support through the annual surveillance audits. Continuing alignment as the standard and your organisation both change.

Your own timeline depends on how much of the groundwork already exists.

Three parties, one system

Certification needs the people who own the risks, the people who deliver the controls and the people who run the management system to be working to the same plan. Most engagements have two of the three and improvise the rest.

An interlocking triangle labelled MSP, Client and ISO Consultant, showing Ericom as the technical team, the client as risk owner and ISO365 as the compliance team
  1. Ericom, your technical team

    Delivers and maintains the infrastructure, and implements the IT and cyber controls that the risk treatments call for. We are in the workshops and the audit preparation, so the evidence exists when the auditor asks for it instead of being reconstructed afterwards.

  2. You, the risk owner

    Bring the operational context, the objectives and the ownership of risk. The standard expects your own leadership to set the objectives, accept the residual risk and sit in the management review; that cannot be outsourced, and a system built without it is a system that passes an audit and does nothing else.

  3. ISO365, your compliance team

    Your virtual compliance officers. They build and maintain the management system, facilitate the risk assessments, internal audits and management reviews, and represent you through the external audits.

The established partnership is the point. There is no ramp-up period and no gap where each side waits for the other to explain itself, which is where most of the time goes in a three-way engagement assembled for one job.

What is included

The full scope, so you can check rather than ask. Everything below is part of the service, and none of it is quoted as it arises.

The system 6

  • A complete ISO management system
  • Registers and compliance documentation
  • A tailored ISMS hub in your SharePoint
  • ISO-aligned policies, registers and tools
  • A dedicated Microsoft Teams channel
  • Gap analysis workshop, two to three hours

The rhythm 4

  • Monthly risk and performance sessions
  • Monthly continuous improvement sessions
  • Quarterly management review meetings
  • Monitoring and measurement of performance

Assurance and audit 5

  • Internal audits with non-conformity logging
  • Stage 1 external audit support
  • Stage 2 external audit support
  • Annual surveillance audit support
  • Training and audit preparation

Delivered entirely within your own Microsoft 365 tenancy. The documentation, the registers and the evidence stay under your control throughout, and they stay with you if the engagement ends.

What this is, and what it is not

A management system, run by people, that takes you to certification and keeps you there.

What it does

  • A system, not a document pack

    Registers that get reviewed monthly, risks that get treated, corrective actions that get closed. A folder of policies passes one audit and fails the next.

  • Inside your own tenancy

    The ISMS hub is in your SharePoint and the collaboration is in your Teams. Your documentation and evidence do not sit on somebody else's platform.

  • Real people, on a rhythm

    Monthly risk and improvement sessions, quarterly management reviews, internal audits. Named people who are in the room every month, so the auditor meets a system that has been operating and not one assembled for the visit.

  • Yours at the end

    The system, the registers and the evidence remain yours. If the engagement stops, your certification foundation does not leave with it.

What it does not do

  • We do not issue the certificate

    ISO 27001 certification is granted by an accredited certification body, which is neither Ericom nor ISO365. We build the system, implement the controls and represent you through the audits. An independent body decides the outcome, and that independence is what makes the certificate worth holding.

  • Not a guarantee of certification

    Certification depends on decisions and evidence that are yours.

  • Not the Essential Eight

    Different thing entirely. The Essential Eight is ASD guidance with no certificate available at all. ISO 27001 is an international standard you can genuinely be certified against. Being asked for one is not being asked for the other.

  • Not a substitute for security controls

    A management system describes and governs your controls. It does not deploy them. The technical work sits with us or with whoever runs your IT, and the standard will ask for evidence that it happened.

  • Not instant, and not off the shelf

    Six months is the typical shape. A platform that promises a certifiable ISMS in a fortnight is selling templates.

Most providers stop at operations

Running your IT well and being able to prove it to an auditor are different jobs, and the second one is where tenders are won and lost. Closing that gap is governance work with a technical dependency: the management system decides what has to be controlled and evidenced, and the technical team has to make it true, which is why it takes both.

Common questions

Short answers first.

How long does ISO 27001 certification take?

Typically six months through this partnership: two months building the system, two embedding it and reaching the Stage 1 audit, two finalising risk treatment and reaching Stage 2.

It moves faster if you already have documented processes, a clear scope and somebody internally who can own decisions. It moves slower if the scope keeps changing, which is the single most common cause of delay.

Who actually issues the certificate?

An accredited certification body, independent of both Ericom and ISO365. They run the Stage 1 and Stage 2 audits and the annual surveillance audits after them. We build the system, implement the controls and represent you through the process. The people who help you prepare cannot also certify you, and that separation is what gives the certificate its value.

Is this the same as the Essential Eight?

No, and the difference matters if somebody has asked you for one of them. The Essential Eight is guidance published by the Australian Signals Directorate, with eight mitigation strategies, three target maturity levels and no certification available at all. ISO 27001 is an international standard with a formal certification process and an accredited body behind it. Some organisations need both, for different reasons, and they are separate pieces of work.

Do we have to move our IT to Ericom?

No. The management system side works alongside whoever runs your IT. Where we do run it, control implementation is faster and the evidence the auditor wants is easier to produce, because the same team doing the technical work is in the workshops. That is an advantage, and it is not a condition of the engagement.

What happens after we are certified?

The rhythm continues, because the standard requires it. Monthly reviews of risk and improvements, quarterly management reviews, internal audits, and support through the annual surveillance audit. Certification is the point at which the system has to keep working, and the surveillance audit a year later checks that it did.

Where does our documentation live?

In your own Microsoft 365 tenancy. The ISMS hub is a SharePoint site in your environment and the working conversation happens in a dedicated Teams channel. Nothing sits on a third-party compliance platform you would have to keep paying for to retain access to your own evidence.

What about ISO 9001, or the other standards?

ISO 27001 for information security is the documented service and the one this page describes. ISO365 works across other standards including quality, environmental and work health and safety, and the same partnership model applies. If you need more than one, say so early: the systems share a great deal and building them together is cheaper than building them twice.

Start with the gap analysis

One workshop, and what comes out of it is a plan, with the scope, the gaps and the dates. It is not a proposal. It also tells you how far off you are, which is occasionally further and occasionally much closer than expected.

  1. Agree the scope

    Which parts of the organisation, which systems, which locations. Getting this wrong is the main reason certifications run long, and it is much cheaper to argue about it now.

  2. Run the gap analysis workshop

    Two to three hours with the people who know how things actually work. It tailors the policies to your operations and populates your registers with real tasks in place of placeholders.

  3. Build, embed, certify

    The six month pathway starts, with monthly sessions and a defined set of audits. You will know at every point what is outstanding and who owns it.

Find out how far off you are

The tender or the contract clause, the date it carries, and the scope somebody has already assumed on your behalf are enough to begin with. A gap analysis tells you what is missing, what you already have that counts, and whether that date is realistic.

Book a gap analysis