ISO 27001
Annual Maintenance
Certification is not the end of the engagement; it is the start of a three-year cycle with a surveillance audit in each of the first two years and recertification in the third. An ISMS that is assembled for the certification audit and left alone decays quietly, and the decay surfaces at the first surveillance audit as a set of findings that were avoidable all year.
Methodology
- 01
Stewardship
Ongoing upkeep of the management system between certification cycles, with a named point of contact.
- 02
Risk Review
Periodic review of the risk assessment against what has actually changed in the organisation and its threat landscape.
- 03
Living Documentation
Documents updated as processes change, rather than rewritten in the weeks before an audit.
- 04
Internal Audit
The internal audit programme run on its cycle, feeding findings into corrective action.
- 05
Management Review
Management review held and recorded, which is itself a mandatory document.
- 06
Surveillance Readiness
Preparation ahead of each surveillance audit, and ahead of recertification in Year 3.
- 07
Continuous Improvement
Recommendations that mature the ISMS year over year rather than holding it at the level that first passed.
Approach to testing
- Requirement — what does the applicable standard, regulation or framework require?
- Control — what control has the organisation established?
- Implementation — how is the control actually implemented?
- Evidence — what evidence demonstrates that the control operates?
- Risk — what happens if the control is ineffective or absent?
- Action — what needs to be changed?
- Validation — has the corrective action actually addressed the issue?
Types of assessment
Black-Box
Assessment begins with limited organisational information, to provide an independent perspective of the governance environment.
Grey-Box
Selected organisational documentation, process information and evidence are provided for structured assessment.
White-Box
Full documentation, evidence, stakeholder and process access is provided for detailed control validation.
Hybrid
Combines independent assessment techniques with detailed evidence and stakeholder validation.
Frameworks and standards
- ISO/IEC 27001:2022
- Clauses 9 and 10 — performance evaluation and improvement — are what maintenance actually delivers against.
- ISO/IEC 27002:2022
- Control guidance, revisited as controls and their owners change.
- CSS Security Governance Toolkit
- Review cadence, decision records and the management review pack.
- CSS Internal Audit Toolkit
- The internal audit programme across the cycle.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
CSS Security Governance Toolkit
Management review pack, decision records and the annual calendar.
CSS Internal Audit Toolkit
Audit programme, findings and corrective action tracking.
PlyoGRC
Where appropriate, the risk register, control evidence and corrective actions are held as controlled records rather than spreadsheets that go stale between audits.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
The certification cycle
- Year 1 — surveillance audit
- Year 2 — surveillance audit
- Year 3 — recertification
- Readiness preparation ahead of each
Kept current
- Risk assessment and risk treatment plan
- Statement of Applicability, as controls and exclusions change
- ISMS scope, where the organisation has changed
- Policies and procedures, as the processes beneath them change
- Asset and supplier registers
- Competence evidence for the roles the ISMS depends on
Run on a cycle
- Internal audit programme
- Management review
- Corrective action tracking to closure
- Monitoring and measurement against the information security objectives
- Security awareness and role-based training
- Supplier reassessment
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Framework Mapping Agent — maps requirements and controls across applicable frameworks.
Policy Analysis Agent — identifies potential missing, inconsistent or outdated requirements.
Evidence Analysis Agent — associates evidence with applicable controls and identifies evidence gaps.
Risk Analysis Agent — identifies recurring risk themes and potential control weaknesses.
Blind-Spot Detection Agent — looks for issues that may not be immediately visible through conventional checklist assessment.
Executive Reporting Agent — helps transform detailed assessment information into concise management reporting.
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
Maintenance, not a pre-audit scramble
The work is spread across the year against a calendar. Compressing it into the month before a surveillance audit is how avoidable findings are created.
Living documentation
Documents are updated as processes change. A document set that is accurate only in audit season is a record of what the organisation once did.
Improvement, not preservation
The objective is an ISMS that matures year over year, not one held at the level that first passed. Clause 10 asks for improvement and an auditor will look for evidence of it.
Operating control, not documentation only
Evidence is validated across five stages: Designed — is it appropriately designed? Implemented — has it been implemented? Operating — is it actually performed? Evidenced — can operation be shown? Effective — is it achieving its goal?
Human-in-the-loop AI assistance
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
What you receive
A working management system, not a folder of documents
The target state is that owners know what they must do, management knows what decisions are pending, and evidence exists to demonstrate that controls operate. Outputs are grouped by who uses them.
Executive layer
Scope, risk posture, roadmap, management decisions, KPI/KRI, readiness summary
GRC layer
Risk register, Statement of Applicability, policies, procedures, ownership, evidence map, action tracker
Assurance layer
Internal audit, findings, CAPA, management review, certification-readiness assessment
Operational layer
Control records, recurring reviews, awareness, supplier / access / incident / continuity evidence as applicable
Governance cadence established
- Monthly
- Risk / action review, evidence status, control exceptions, material incidents
- Quarterly
- Risk trend, supplier / control reviews, KPI/KRI, management action tracking
- Annual
- Internal audit programme, management review, ISMS objectives, risk refresh, improvement plan
For this engagement specifically
- Control owners
- IT teams
- Security teams
- Compliance teams
- Process owners
- Auditors
- Key risks
- Significant gaps
- Business impact
- Priority actions
- Ownership
- Target timelines
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.