[ Non-Profit ]

Ensuring ISO 27001 Compliance for a Non-Profit

client: Confidential

Problem / Challenge:

The client required compliance with ISO 27001 and ACSC ISM standards to improve their information security posture and safeguard sensitive data of their clients. Their existing infrastructure lacked essential controls, leaving them vulnerable to data breaches and security incidents. They needed a comprehensive solution that could not only meet audit standards but also support long-term security management and risk mitigation.

Solution:

As the project lead and engineering specalist, Smarterdata took the following approach to meet the client’s needs:

Project Scoping and Risk Assessment:

The first step involved scoping the project and performing a detailed risk assessment to identify vulnerabilities and prioritize areas for improvement. This included evaluating existing infrastructure, identifying missing controls, and determining the risk appetite for the organization.

Implementation of ISO 27001 Controls and ACSC ISM:

Leveraging Microsoft Endpoint Manager (Intune) and Group Policy, we deployed and managed security controls such as firewalls, intrusion detection systems, and access control measures. These technical solutions were tailored to the client’s unique needs and fully aligned with both ISO 27001 and ISM requirements.

Stakeholder Engagement:

Throughout the project, I led stakeholder engagement efforts to ensure buy-in from all levels of the organization. This involved clear communication of the Statement of Applicability (SOA) and ongoing updates about the progress of the control implementation.

Technical Implementation and Testing:

I took the lead in technically implementing the controls, including continuous testing to ensure they were functioning effectively and compliant with audit standards. This phase also included preparing the necessary documentation and evidence to meet audit requirements.

Audit Preparation and Participation:

During the external ISO 27001 audit, I worked closely with the auditor, presenting evidence and answering questions to ensure a smooth audit process. Post-audit, I addressed any issues that were identified and implemented improvements to strengthen the organization’s security posture.

results:

The client successfully passed the ISO 27001 audit, achieving full compliance with both ISO 27001 and ACSC ISM. Specific outcomes included:

Enhanced Security Posture:

The client now operates with a robust Information Security Management System (ISMS) that significantly reduces their exposure to data breaches and cyber threats.

Audit-Ready Compliance:

By the time of the audit, all necessary controls were fully implemented, tested, and documented, allowing the client to pass with minimal adjustments.

Ongoing Security Monitoring:

Thanks to the integration of Microsoft Endpoint Manager, the client has real-time monitoring and automated security management, allowing them to maintain continuous compliance.

Stakeholder Confidence:

The project resulted in a higher level of trust and confidence from internal and external stakeholders, including board members and regulators.

testimony:

“Jack at Smarterdata were integral to our ISO 27001 accreditation process. Their expertise in both technical implementation and stakeholder management ensured that we not only passed the audit but also significantly strengthened our security practices. Jack’s ability to communicate complex ideas clearly and work effectively across all levels of the organization was key to the project’s success.” 

“We not only passed the audit but also significantly strengthened our security practices.”