All services
Security & compliance

Build an ISMS that works beyond the audit.

Move from scattered security controls to an operational information security management system ready for ISO/IEC 27001:2022 certification.

Discuss this service
ISO 27001 readiness dashboard with risk matrix, control progress, and audit indicators
The challenge

What we help you move beyond.

01

Policies and controls exist, but ownership and evidence are inconsistent.

02

Security risks are understood informally rather than managed through a repeatable process.

03

Audit preparation competes with day-to-day operations and creates last-minute pressure.

What we deliver

Practical work. Tangible outputs.

The exact scope adapts to your environment, maturity, and operating model.

01

ISO 27001:2022 gap and maturity assessment

02

ISMS scope, risk methodology, and risk treatment plan

03

Policy, control, evidence, and ownership framework

04

Internal audit preparation and certification-body support

The result

Designed around outcomes that last.

  • A clear, prioritized path to certification readiness
  • Controls that fit how your company actually operates
  • Evidence and accountability that remain useful after the audit
Engagement flow

A clear path from current state to capability.

  1. 01

    Assess

    Establish scope, stakeholders, current controls, and the material gaps.

  2. 02

    Design

    Create the ISMS structure, risk model, policies, and control ownership.

  3. 03

    Implement

    Embed processes, collect evidence, and close priority findings.

  4. 04

    Prepare

    Run readiness checks and support the independent certification audit.

Northstar supports certification readiness and implementation. Certification is issued by an independent accredited certification body.

Next capability

Intune device management