Consultancy Services
- ISO 9001:2026
- IATF 16949:2016
- ISO 14001:2026
- ISO 45001:2018
- ISO 13485:2016
- ISO 21001:2025
- ISO 22000:2018
- ISO 27001:2022
- ISO 50001:2018
- AS 9100D:2016
- CE marking
ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection — Information security management systems
Protect your data, earn client trust, and win security-conscious business with a certified Information Security Management System (ISMS).
GREEN TQM GROUP provides practical ISO/IEC 27001:2022 consultancy in Chennai for organizations seeking to establish, implement, ISMS training, maintain and continually improve an Information Security Management System (ISMS).
Our consultancy approach covers ISMS gap assessment, information-security risk assessment, Statement of Applicability (SoA), information-security policies and procedures, Annex A controls, employee awareness, internal audit, corrective action, management review and certification-audit preparation.
What is ISO/IEC 27001:2022 (ISMS)?
ISO 27001:2022 is the world's leading standard for Information Security Management Systems (ISMS). It provides a structured framework to identify, manage, and reduce information security risks — covering data confidentiality, integrity, and availability across people, processes, and technology.
An ISMS provides a systematic approach for managing information-security risks and protecting information based on the principles of confidentiality, integrity, and availability.
- Confidentiality: Information is accessible only to authorized people and entities.
- Integrity: Information remains accurate, complete and protected against unauthorized modification.
- Availability: Information and information systems are available when required by authorized users.
The 2022 revision updated the standard's controls (Annex A) to reflect modern threats, including cloud security, threat intelligence, and data leakage prevention. It's essential for IT companies, SaaS providers, BPOs, financial services, healthcare, and any business that handles sensitive customer or corporate data.
Why Your Business Needs ISO/IEC 27001:2022 (ISMS)
Benefits of ISO 27001:2022 Certification
- Win Enterprise & Global Clients – Increasingly a mandatory requirement in IT, SaaS, BPO vendor contracts, automotive and non-automotive.
- Reduce Data Breach Risk – Systematic identification and control of information security risks.
- Regulatory Alignment – Supports compliance with data protection laws (e.g., DPDP Act, GDPR-linked contracts).
- Competitive Advantage – Differentiates you in tenders and RFQs where security posture matters.
- Customer Trust – Demonstrates that sensitive data is handled with rigor and accountability.
- Reduced Incident Costs – Fewer breaches mean lower financial, legal, and reputational damage.
- Global Recognition – Internationally accepted ISMS standard across 170+ countries.
Our ISO/IEC 27001:2022 (ISMS) Consulting Services
- ISMS Gap Analysis – Assess current information security practices against ISO 27001:2022 requirements and the updated Annex A controls.
- Risk Assessment & Treatment – Identify information assets, assess risks, and build a risk treatment plan aligned to your business context.
- Statement of Applicability (SoA) – Determine which of the 93 Annex A controls apply to your organization and document justification.
- Documentation Support – ISMS policy, procedures, risk register, and records - tailored to your systems and data flows.
- Employee Training & Awareness – Security awareness sessions, role-based training, and internal auditor training.
- Implementation Support – Hands-on rollout of technical, physical, and organizational controls across your environment.
- Internal Audits – Pre-certification audits to catch and resolve non-conformities early.
- Certification Body Liaison – Support selecting an accredited (NABCB/IAF-recognized) certification body and guidance through Stage 1 & Stage 2 audits.
- Post-Certification Support – Surveillance audit prep, continual improvement, and control effectiveness reviews.
What is a Statement of Applicability (SoA)?
The Statement of Applicability (SoA) is a mandatory document required by ISO 27001:2022. It lists all 93 Annex A controls and states, for each one, whether the control is applicable to your organization, whether it has been implemented, and the justification for including or excluding it, based on your risk assessment.
The SoA is one of the first documents an auditor reviews - it's the bridge between your risk assessment and the actual controls operating in your business. A weak or inconsistent SoA is one of the most common reasons organizations fail or delay certification.
ISO/IEC 27001:2022 Annex A Controls
ISO/IEC 27001:2022 Annex A contains 93 information-security controls grouped into four themes: Organizational, People, Physical and Technological controls.
| Theme / Controls | Controls Ref | No. of Controls |
|---|---|---|
| A.5 Organizational controls | A.5.1 – A.5.37 | 37 |
| A.6 People controls | A.6.1 – A.6.8 | 8 |
| A.7 Physical controls | A.7.1 – A.7.14 | 14 |
| A.8 Technological controls | A.8.1 – A.8.34 | 34 |
| Total | 93 |
A.5 – Organizational Controls
| Control | Name |
|---|---|
| A.5.1 | Policies for information security |
| A.5.2 | Information security roles and responsibilities |
| A.5.3 | Segregation of duties |
| A.5.4 | Management responsibilities |
| A.5.5 | Contact with authorities |
| A.5.6 | Contact with special interest groups |
| A.5.7 | Threat intelligence |
| A.5.8 | Information security in project management |
| A.5.9 | Inventory of information and other associated assets |
| A.5.10 | Acceptable use of information and other associated assets |
| A.5.11 | Return of assets |
| A.5.12 | Classification of information |
| A.5.13 | Labelling of information |
| A.5.14 | Information transfer |
| A.5.15 | Access control |
| A.5.16 | Identity management |
| A.5.17 | Authentication information |
| A.5.18 | Access rights |
| A.5.19 | Information security in supplier relationships |
| A.5.20 | Addressing information security within supplier agreements |
| A.5.21 | Managing information security in the ICT supply chain |
| A.5.22 | Monitoring, review and change management of supplier services |
| A.5.23 | Information security for use of cloud services |
| A.5.24 | Information security incident management planning and preparation |
| A.5.25 | Assessment and decision on information security events |
| A.5.26 | Response to information security incidents |
| A.5.27 | Learning from information security incidents |
| A.5.28 | Collection of evidence |
| A.5.29 | Information security during disruption |
| A.5.30 | ICT readiness for business continuity |
| A.5.31 | Legal, statutory, regulatory and contractual requirements |
| A.5.32 | Intellectual property rights |
| A.5.33 | Protection of records |
| A.5.34 | Privacy and protection of PII |
| A.5.35 | Independent review of information security |
| A.5.36 | Compliance with policies, rules and standards for information security |
| A.5.37 | Documented operating procedures |
A.6 – People Controls
| Control | Title |
|---|---|
| A.6.1 | Screening |
| A.6.2 | Terms and conditions of employment |
| A.6.3 | Information security awareness, education and training |
| A.6.4 | Disciplinary process |
| A.6.5 | Responsibilities after termination or change of employment |
| A.6.6 | Confidentiality or non-disclosure agreements |
| A.6.7 | Remote working |
| A.6.8 | Information security event reporting |
A.7 – Physical Controls
| Control | Title |
|---|---|
| A.7.1 | Physical security perimeters |
| A.7.2 | Physical entry |
| A.7.3 | Securing offices, rooms and facilities |
| A.7.4 | Physical security monitoring |
| A.7.5 | Protecting against physical and environmental threats |
| A.7.6 | Working in secure areas |
| A.7.7 | Clear desk and clear screen |
| A.7.8 | Equipment siting and protection |
| A.7.9 | Security of assets off-premises |
| A.7.10 | Storage media |
| A.7.11 | Supporting utilities |
| A.7.12 | Cabling security |
| A.7.13 | Equipment maintenance |
| A.7.14 | Secure disposal or re-use of equipment |
A.8 – Technological Controls
| Control | Title |
|---|---|
| A.8.1 | User end point devices |
| A.8.2 | Privileged access rights |
| A.8.3 | Information access restriction |
| A.8.4 | Access to source code |
| A.8.5 | Secure authentication |
| A.8.6 | Capacity management |
| A.8.7 | Protection against malware |
| A.8.8 | Management of technical vulnerabilities |
| A.8.9 | Configuration management |
| A.8.10 | Information deletion |
| A.8.11 | Data masking |
| A.8.12 | Data leakage prevention |
| A.8.13 | Information backup |
| A.8.14 | Redundancy of information processing facilities |
| A.8.15 | Logging |
| A.8.16 | Monitoring activities |
| A.8.17 | Clock synchronization |
| A.8.18 | Use of privileged utility programs |
| A.8.19 | Installation of software on operational systems |
| A.8.20 | Network security |
| A.8.21 | Security of network services |
| A.8.22 | Segregation of networks |
| A.8.23 | Web filtering |
| A.8.24 | Use of cryptography |
| A.8.25 | Secure development life cycle |
| A.8.26 | Application security requirements |
| A.8.27 | Secure system architecture and engineering principles |
| A.8.28 | Secure coding |
| A.8.29 | Security testing in development and acceptance |
| A.8.30 | Outsourced development |
| A.8.31 | Separation of development, test and production environments |
| A.8.32 | Change management |
| A.8.33 | Test information |
| A.8.34 | Protection of information systems during audit testing |
Steps to Get ISO/IEC 27001:2022 (ISMS) Certification
| Step | What Happens |
|---|---|
| 1. Kickoff | Understand your systems, data flows, and security posture |
| 2. Gap Analysis | Evaluate current practices vs. ISO 27001:2022 requirements |
| 3. Risk Assessment | Identify information assets and assess security risks |
| 4. Statement of Applicability | Determine applicable Annex A controls |
| 5. Documentation | Build ISMS policy, procedures, and risk treatment plan |
| 6. Training | Train staff and internal auditors on security practices |
| 7. Implementation | Roll out technical and organizational controls |
| 8. Internal Audit | Identify and close gaps before certification audit |
| 9. Certification Audit | Support during Stage 1 & Stage 2 audits |
| 10. Certified! | Receive your ISO 27001:2022 certificate |
Typical timeline: 10–24 weeks, depending on system complexity and data scope.
Why Choose Us (Green Tqm Group)
- 20+ years of experience in ISMS/information security consulting
- 1000+ successful ISO 27001 certifications across IT and Non-IT company
- Consultants experienced in IT security, risk management, and compliance
- Practical, right-sized controls - not generic checklists
- End-to-end support from gap analysis to certification and beyond
- Transparent, fixed-fee pricing
- Local presence in Chennai with pan-India service capability
Industries We Serve
- IT & Software Development
- SaaS & Cloud Service Providers
- BPO & IT-Enabled Services
- Financial Services & Fintech
- Healthcare & Health-Tech
- E-commerce
- Data Centers & Managed Services
- Professional Services








