I will create your iso 27001 isms documentation, risk assessment and policies

D
douetts
D
douetts
Michel D

About this gig

Preparing for ISO 27001 certification and not sure what the auditor will ask for? I've been on both sides of the table: 7 years auditing IT controls at PwC, and today I run the ISO 27001, ISO 27701 and PCI DSS certification programme of a payments company, whose latest ISO 27001 audit closed with no major non-conformities.


I work with ISO/IEC 27001:2022 and write documents that fit your company's size, not a 300-page template nobody reads.


What you get:

  • Gap analysis of clauses 4-10 and the 93 Annex A controls
  • - ISMS scope and information security policy
  • - Risk assessment methodology and risk register
  • - Statement of Applicability (SoA)
  • - Annex A policies and procedures (Premium)
  • - 90-day roadmap to your Stage 1 audit (Premium)
  • - Editable Word and Excel files

How it works:

  1. You answer a short questionnaire about your company, systems and current controls
  2. 2. I prepare the documents and we review them together
  3. 3. You get the final files, ready for your auditor

Message me before ordering if you want to talk about scope.

Get to know Michel D

Michel D

Technology Risk GRC Specialist

  • FromBrazil
  • Member sinceSep 2026
  • Avg. response time1 hour
  • Languages

    English, Portuguese
Technology risk and GRC specialist with 13 years across Big 4 audit, payments and healthcare. At PwC I audited IT controls on 50+ engagements; today I run the ISO 27001, ISO 27701 and PCI DSS certification programme of a payments company; before that I spent 6 years leading privacy and security risk at a large hospital group. I help companies get audit-ready for ISO 27001, SOC 2, PCI DSS, GDPR, CCPA and HIPAA, with documents written for your business, not generic templates.

My Portfolio