Consultancy Services

Home / Consultants

ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection — Information security management systems

Protect your data, earn client trust, and win security-conscious business with a certified Information Security Management System (ISMS).

GREEN TQM GROUP provides practical ISO/IEC 27001:2022 consultancy in Chennai for organizations seeking to establish, implement, ISMS training, maintain and continually improve an Information Security Management System (ISMS).

Our consultancy approach covers ISMS gap assessment, information-security risk assessment, Statement of Applicability (SoA), information-security policies and procedures, Annex A controls, employee awareness, internal audit, corrective action, management review and certification-audit preparation.

What is ISO/IEC 27001:2022 (ISMS)?

ISO 27001:2022 is the world's leading standard for Information Security Management Systems (ISMS). It provides a structured framework to identify, manage, and reduce information security risks — covering data confidentiality, integrity, and availability across people, processes, and technology.

An ISMS provides a systematic approach for managing information-security risks and protecting information based on the principles of confidentiality, integrity, and availability.

  • Confidentiality: Information is accessible only to authorized people and entities.
  • Integrity: Information remains accurate, complete and protected against unauthorized modification.
  • Availability: Information and information systems are available when required by authorized users.

The 2022 revision updated the standard's controls (Annex A) to reflect modern threats, including cloud security, threat intelligence, and data leakage prevention. It's essential for IT companies, SaaS providers, BPOs, financial services, healthcare, and any business that handles sensitive customer or corporate data.

Why Your Business Needs ISO/IEC 27001:2022 (ISMS)

Benefits of ISO 27001:2022 Certification

  • Win Enterprise & Global Clients – Increasingly a mandatory requirement in IT, SaaS, BPO vendor contracts, automotive and non-automotive.
  • Reduce Data Breach Risk – Systematic identification and control of information security risks.
  • Regulatory Alignment – Supports compliance with data protection laws (e.g., DPDP Act, GDPR-linked contracts).
  • Competitive Advantage – Differentiates you in tenders and RFQs where security posture matters.
  • Customer Trust – Demonstrates that sensitive data is handled with rigor and accountability.
  • Reduced Incident Costs – Fewer breaches mean lower financial, legal, and reputational damage.
  • Global Recognition – Internationally accepted ISMS standard across 170+ countries.

Our ISO/IEC 27001:2022 (ISMS) Consulting Services

  • ISMS Gap Analysis – Assess current information security practices against ISO 27001:2022 requirements and the updated Annex A controls.
  • Risk Assessment & Treatment – Identify information assets, assess risks, and build a risk treatment plan aligned to your business context.
  • Statement of Applicability (SoA) – Determine which of the 93 Annex A controls apply to your organization and document justification.
  • Documentation Support – ISMS policy, procedures, risk register, and records - tailored to your systems and data flows.
  • Employee Training & Awareness – Security awareness sessions, role-based training, and internal auditor training.
  • Implementation Support – Hands-on rollout of technical, physical, and organizational controls across your environment.
  • Internal Audits – Pre-certification audits to catch and resolve non-conformities early.
  • Certification Body Liaison – Support selecting an accredited (NABCB/IAF-recognized) certification body and guidance through Stage 1 & Stage 2 audits.
  • Post-Certification Support – Surveillance audit prep, continual improvement, and control effectiveness reviews.

What is a Statement of Applicability (SoA)?

The Statement of Applicability (SoA) is a mandatory document required by ISO 27001:2022. It lists all 93 Annex A controls and states, for each one, whether the control is applicable to your organization, whether it has been implemented, and the justification for including or excluding it, based on your risk assessment.

The SoA is one of the first documents an auditor reviews - it's the bridge between your risk assessment and the actual controls operating in your business. A weak or inconsistent SoA is one of the most common reasons organizations fail or delay certification.

ISO/IEC 27001:2022 Annex A Controls

ISO/IEC 27001:2022 Annex A contains 93 information-security controls grouped into four themes: Organizational, People, Physical and Technological controls.

Theme / ControlsControls RefNo. of Controls
A.5 Organizational controlsA.5.1 – A.5.3737
A.6 People controlsA.6.1 – A.6.88
A.7 Physical controlsA.7.1 – A.7.1414
A.8 Technological controlsA.8.1 – A.8.3434
Total93

A.5 – Organizational Controls

Control Name
A.5.1Policies for information security
A.5.2Information security roles and responsibilities
A.5.3Segregation of duties
A.5.4Management responsibilities
A.5.5Contact with authorities
A.5.6Contact with special interest groups
A.5.7Threat intelligence
A.5.8Information security in project management
A.5.9Inventory of information and other associated assets
A.5.10Acceptable use of information and other associated assets
A.5.11Return of assets
A.5.12Classification of information
A.5.13Labelling of information
A.5.14Information transfer
A.5.15Access control
A.5.16Identity management
A.5.17Authentication information
A.5.18Access rights
A.5.19Information security in supplier relationships
A.5.20Addressing information security within supplier agreements
A.5.21Managing information security in the ICT supply chain
A.5.22Monitoring, review and change management of supplier services
A.5.23Information security for use of cloud services
A.5.24Information security incident management planning and preparation
A.5.25Assessment and decision on information security events
A.5.26Response to information security incidents
A.5.27Learning from information security incidents
A.5.28Collection of evidence
A.5.29Information security during disruption
A.5.30ICT readiness for business continuity
A.5.31Legal, statutory, regulatory and contractual requirements
A.5.32Intellectual property rights
A.5.33Protection of records
A.5.34Privacy and protection of PII
A.5.35Independent review of information security
A.5.36Compliance with policies, rules and standards for information security
A.5.37Documented operating procedures

A.6 – People Controls

ControlTitle
A.6.1Screening
A.6.2Terms and conditions of employment
A.6.3Information security awareness, education and training
A.6.4Disciplinary process
A.6.5Responsibilities after termination or change of employment
A.6.6Confidentiality or non-disclosure agreements
A.6.7Remote working
A.6.8Information security event reporting

A.7 – Physical Controls

ControlTitle
A.7.1Physical security perimeters
A.7.2Physical entry
A.7.3Securing offices, rooms and facilities
A.7.4Physical security monitoring
A.7.5Protecting against physical and environmental threats
A.7.6Working in secure areas
A.7.7Clear desk and clear screen
A.7.8Equipment siting and protection
A.7.9Security of assets off-premises
A.7.10Storage media
A.7.11Supporting utilities
A.7.12Cabling security
A.7.13Equipment maintenance
A.7.14Secure disposal or re-use of equipment

A.8 – Technological Controls

ControlTitle
A.8.1User end point devices
A.8.2Privileged access rights
A.8.3Information access restriction
A.8.4Access to source code
A.8.5Secure authentication
A.8.6Capacity management
A.8.7Protection against malware
A.8.8Management of technical vulnerabilities
A.8.9Configuration management
A.8.10Information deletion
A.8.11Data masking
A.8.12Data leakage prevention
A.8.13Information backup
A.8.14Redundancy of information processing facilities
A.8.15Logging
A.8.16Monitoring activities
A.8.17Clock synchronization
A.8.18Use of privileged utility programs
A.8.19Installation of software on operational systems
A.8.20Network security
A.8.21Security of network services
A.8.22Segregation of networks
A.8.23Web filtering
A.8.24Use of cryptography
A.8.25Secure development life cycle
A.8.26Application security requirements
A.8.27Secure system architecture and engineering principles
A.8.28Secure coding
A.8.29Security testing in development and acceptance
A.8.30Outsourced development
A.8.31Separation of development, test and production environments
A.8.32Change management
A.8.33Test information
A.8.34Protection of information systems during audit testing

Steps to Get ISO/IEC 27001:2022 (ISMS) Certification

StepWhat Happens
1. KickoffUnderstand your systems, data flows, and security posture
2. Gap AnalysisEvaluate current practices vs. ISO 27001:2022 requirements
3. Risk AssessmentIdentify information assets and assess security risks
4. Statement of ApplicabilityDetermine applicable Annex A controls
5. DocumentationBuild ISMS policy, procedures, and risk treatment plan
6. TrainingTrain staff and internal auditors on security practices
7. ImplementationRoll out technical and organizational controls
8. Internal AuditIdentify and close gaps before certification audit
9. Certification AuditSupport during Stage 1 & Stage 2 audits
10. Certified!Receive your ISO 27001:2022 certificate

Typical timeline: 10–24 weeks, depending on system complexity and data scope.

Why Choose Us (Green Tqm Group)

  • 20+ years of experience in ISMS/information security consulting
  • 1000+ successful ISO 27001 certifications across IT and Non-IT company
  • Consultants experienced in IT security, risk management, and compliance
  • Practical, right-sized controls - not generic checklists
  • End-to-end support from gap analysis to certification and beyond
  • Transparent, fixed-fee pricing
  • Local presence in Chennai with pan-India service capability

Industries We Serve

  • IT & Software Development
  • SaaS & Cloud Service Providers
  • BPO & IT-Enabled Services
  • Financial Services & Fintech
  • Healthcare & Health-Tech
  • E-commerce
  • Data Centers & Managed Services
  • Professional Services

Frequently Asked Questions

Typically, 12–24 weeks, depending on the complexity of your IT systems, number of locations, and how much documentation and control implementation is already in place.

The 2022 revision restructured Annex A from 114 controls into 93, grouped into four themes (organizational, people, physical, technological), and added 11 new controls covering areas like threat intelligence, cloud security, and data masking.

No. You select and justify applicable controls based on your risk assessment, documented in your Statement of Applicability (SoA). Controls not relevant to your business can be formally excluded with justification.

Yes. Both share the same high-level structure (Annex SL), making it efficient to run an Integrated Management System covering quality and information security together — we can support this.

Not necessarily. Many organizations designate an existing IT or compliance lead as ISMS Manager/CISO, supported by our team during implementation, audits, and ongoing risk reviews.

Yes, organizations certified to the 2013 version are required to transition to ISO 27001:2022 within a set deadline set by certification bodies (typically a 3-year transition window from publication). We can support this transition.

Look for NABCB (India) or IAF-member accreditation. We only work with accredited certification bodies to ensure your certificate is internationally recognized.