Discovery & assessment
Define the ISMS scope, assess current practices and produce a prioritised gap report and remediation roadmap.
ISO 27001 & ISMS
Build an information security management system that strengthens controls, earns customer confidence and prepares your organisation for independent certification.
Discuss ISO 27001 ↗Designed for your context
For Philippine businesses facing enterprise due diligence, regulated institutions strengthening controls, and government-facing organisations preparing for greater scrutiny.
Define the ISMS scope, assess current practices and produce a prioritised gap report and remediation roadmap.
Develop the information-security risk register, treatment plan and Statement of Applicability.
Build a usable security manual, policy library, procedures, records and management responsibilities.
Help control owners put policies into practice and organise the evidence that demonstrates operation.
Prepare staff and leadership with role-relevant training, materials and attendance records.
Assess implementation, document findings and establish corrective actions with clear ownership.
Prepare the readiness checklist, coordinate with the chosen certification body and support the audit process.
Support surveillance preparation, recertification planning and improvement after the initial certification cycle.
Tangible outputs
Agree scope and leadership commitment
Assess risk and design the ISMS
Implement, train and collect evidence
Audit, improve and prepare for certification
Keep the programme relevant to your customers, operating risks and applicable Philippine obligations. Certification is granted by an independent certification body; advisory support does not guarantee certification.
Yes. Discovery establishes what is already working and where the gaps are. Existing documents and controls are reused where suitable rather than replaced for appearance alone.
No. Gardoce supports implementation and readiness. An independent certification body evaluates the organisation and makes the certification decision.
Support can include surveillance-audit preparation, corrective actions, recertification planning and continual improvement, with the scope agreed separately.
Every engagement starts with a clear scope, agreed responsibilities and practical outcomes.
Start with a conversation
Tell us the decision, risk or operational challenge you are facing. We will help define a sensible next step.
Discuss your priorities ↗