ISMS context, scope and interested-party analysis
INFORMATION SECURITY CONSULTING
ISO/IEC 27001 consulting for an ISMS that customers and teams can understand.
LETA helps organisations define a defensible ISMS scope, assess information-security risk and connect selected controls to accountable owners and evidence. The work is aligned to business operations rather than copied control templates.
WHEN THIS HELPS
Situations we can help you resolve.
- ✓Enterprise customers request ISO 27001
- ✓Security questionnaires are slowing sales
- ✓Cloud, supplier or access risks need clearer ownership
- ✓Policies exist but evidence is fragmented
WHAT YOU RECEIVE
A clear consultancy scope with usable outputs.
Deliverables are confirmed in writing and adjusted to the standard, scope, team size, operating model and evidence already available.
Asset-informed risk methodology and risk treatment plan
Statement of Applicability support
Proportionate policies and operational controls
Security objectives, metrics and evidence map
Internal audit and management-review support
BUSINESS OUTCOMES
Designed to improve the way the system works.
DIRECT ANSWERS
Questions about this service.
Does ISO 27001 require every Annex A control?+
No. Controls are selected through risk treatment and other applicable requirements. The Statement of Applicability records the inclusion or exclusion rationale.
Can LETA perform penetration testing?+
Penetration testing is a specialist technical service. LETA can define the management-system requirement and coordinate evidence, while testing should be performed by a competent technical provider.
Can an ISMS use existing security policies?+
Yes. Existing material is reviewed first and retained where it is accurate, owned and useful.
START WITH CLARITY
Tell us what triggered the requirement.
A tender, customer request, operational issue or audit date is enough to start the conversation.