ISO 27001 & ISMS

Trust that stands up to scrutiny.

Build an information security management system that strengthens controls, earns customer confidence and prepares your organisation for independent certification.

Discuss ISO 27001

Designed for your context

The right support
for the decision ahead.

For Philippine businesses facing enterprise due diligence, regulated institutions strengthening controls, and government-facing organisations preparing for greater scrutiny.

What we deliver

Scope tailored to your organisation

Discovery & assessment

Define the ISMS scope, assess current practices and produce a prioritised gap report and remediation roadmap.

Risk assessment

Develop the information-security risk register, treatment plan and Statement of Applicability.

ISMS design & documentation

Build a usable security manual, policy library, procedures, records and management responsibilities.

Control implementation

Help control owners put policies into practice and organise the evidence that demonstrates operation.

Training & awareness

Prepare staff and leadership with role-relevant training, materials and attendance records.

Internal audit

Assess implementation, document findings and establish corrective actions with clear ownership.

Certification readiness

Prepare the readiness checklist, coordinate with the chosen certification body and support the audit process.

Continual improvement

Support surveillance preparation, recertification planning and improvement after the initial certification cycle.

Tangible outputs

Leave with more
than recommendations.

  • ISMS scope and gap assessment
  • Risk register, treatment plan and SoA
  • Policy and evidence library
  • Internal audit and corrective action plan
  • Certification-readiness review

A clear path to progress

  1. 01

    Agree scope and leadership commitment

  2. 02

    Assess risk and design the ISMS

  3. 03

    Implement, train and collect evidence

  4. 04

    Audit, improve and prepare for certification

Philippine context & engagement boundaries

Keep the programme relevant to your customers, operating risks and applicable Philippine obligations. Certification is granted by an independent certification body; advisory support does not guarantee certification.

Questions worth asking

Can we start before we have complete policies?

Yes. Discovery establishes what is already working and where the gaps are. Existing documents and controls are reused where suitable rather than replaced for appearance alone.

Do you issue the ISO certificate?

No. Gardoce supports implementation and readiness. An independent certification body evaluates the organisation and makes the certification decision.

What happens after certification?

Support can include surveillance-audit preparation, corrective actions, recertification planning and continual improvement, with the scope agreed separately.

Every engagement starts with a clear scope, agreed responsibilities and practical outcomes.

Start with a conversation

What needs to move
forward in your organisation?

Tell us the decision, risk or operational challenge you are facing. We will help define a sensible next step.

Discuss your priorities