Tel +852 5382 0328 info@safeharbour.hk WhatsApp 繁體中文
Safe Harbour Consultants · Hong Kong & Macau Get a Quote

ISO/IEC 27001 Information Security Management

The international standard for an information security management system (ISMS). It sets out how you identify information security risk and put controls in place to manage it.

Client due diligence questionnaires increasingly ask how third-party data is protected.

Who asks for it

Payment and remittance companies, fintech and digital-asset platforms, IT service providers, SaaS vendors, professional services firms, and anyone whose clients have started asking.

Typical duration

3–6 months

What a readiness engagement produces

  • A written gap analysis with priorities
  • Documentation written for your operation
  • Training so staff can explain the system
  • Internal audit and management review
  • An evidence pack ready for the auditor

The two fees

The certification fee is charged by the accredited certification body that audits you and issues the certificate. Our consultancy fee covers gap analysis, documentation, training, internal audit and audit support.

Consultancy fee refund commitment

If your organisation is not recommended for certification at the first certification audit, we refund our consultancy fee in full.

Conditions: the agreed corrective actions are completed, the required records and evidence are provided, and the audit is conducted by an accredited certification body within three months of our readiness sign-off. The commitment covers our consultancy fee only, not the certification body's fees.

Preparing for ISO/IEC 27001?

Tell us the scope and we will give you a written quotation.