I will create iso 27001 isms policies and documentation


About this gig
Need ISO 27001 but not sure where to start? I help IT and SaaS companies build a complete, audit-ready Information Security Management System (ISMS) with documents tailored to your business, not generic templates.
As an ISO 27001 and 42001 Implementer with 7+ years of DevSecOps experience, I understand both the documents and the technical controls behind them.
What I deliver:
Gap analysis against ISO 27001:2022
ISMS scope, context and security policy
Risk assessment and risk treatment plan
Statement of Applicability for all 93 Annex A controls
Policies and procedures (access control, incident response, backup and more)
Internal audit and certification readiness
Why work with me?
Practical documents your team will actually use
Controls mapped to real tools like SIEM and vulnerability scanning
Video consultation included in every package
Certification is issued by an accredited body. I prepare you fully for that audit.
Message me before ordering to discuss your scope.
Get to know Julon Kormokar
DevSecOps and Kubernetes Engineer, ISO 27001 and 42001 Implementer
- FromBangladesh
- Member sinceNov 2018
Languages
Bengali, English
My Portfolio
FAQ
Will you get my company ISO 27001 certified?
Certification can only be issued by an accredited certification body. I prepare your company fully for that audit with complete documentation, risk assessment, and internal audit, so you can approach the certification body with confidence.
Do you use generic templates?
No. Every document is tailored to your company's size, industry, systems, and risks. Generic templates often fail audits because they don't reflect how your business actually works.
Which version of ISO 27001 do you follow?
I work with the latest version, ISO/IEC 27001:2022, including all 93 Annex A controls. If you are transitioning from the 2013 version, I can help with that too.
What information do you need from me to start?
Your company size, industry, main systems and services, and any existing security policies. After ordering, I'll share a short questionnaire and we can discuss the details in a video call.
Is my company information kept confidential?
Yes, absolutely. All information you share is used only for your project and is never shared with anyone. I'm happy to sign an NDA if your company requires one.
Do you also offer ISO 42001 for AI companies?
Yes. As an ISO 42001 Implementer, I can extend your ISMS with AI Management System documentation. You can add it as a gig extra or message me for a custom offer.

