I will audit m365 for iso 27001, soc 2, and cyber essentials
Enterprise M365 and AI Security Specialist Ex Lockheed Martin
Vetted by Fiverr Pro
Adam Grimes was selected by the Fiverr Pro team for their expertise.
Vetted for
Support & IT
About this Gig
Vetted Pro
Audit failure is not an option. Whether you are chasing ISO 27001:2022, SOC 2 Type II, or the UKs Cyber Essentials Plus, your Microsoft 365 configuration is the primary evidence bank.
As a security veteran with 20+ years in aerospace-grade IT, I provide deep-tier auditing using the CIS Microsoft 365 Foundations v6.0.0 benchmark.
What I Cover:
- ISO 27001: Annex A technical control mapping & evidence collection.
- SOC 2 Type II: Trust Services Criteria (Security, Availability, Confidentiality) audit.
- Cyber Essentials Plus: Pre-assessment for the "14-Day Patching Rule" and MFA enforcement.
- Governance: Purview Data Loss Prevention (DLP) and Insider Risk setup.
- Entra ID: Conditional Access hardening and Privileged Identity Management (PIM).
The Deliverable: A comprehensive audit report, a prioritized remediation roadmap, and then full remediation and documentation needed to hit a 90%+ Secure Score.
I specialize in passing audits on the first attempt.
Please message me for a custom scope assessment before ordering.
Device:
Desktop
•
Laptop
•
Server
•
Mobile
•
Tablet
Operating system:
Other
My Portfolio
Other Support & IT Services I Offer
FAQ
Can you help with the UK Cyber Essentials Plus (CE+) technical audit?
Yes. I perform a "Pre-Audit" scan that mirrors the official assessor's vulnerability tests. We fix CVSS 7.0+ vulnerabilities and automate your patching via Intune to ensure you pass the manual verification.
What is the benefit of the CIS v6.0.0 benchmark?
v6.0.0 is the most current standard (Late 2025). It includes critical new checks for AI/Copilot governance and Microsoft Fabric, ensuring your audit covers the latest tech stack risks.
Do you provide the ISMS documentation for ISO 27001?
Yes, in the Premium Package, I provide a full suite of M365-specific policy templates (Access Control, Encryption, Asset Management) required for the Information Security Management System (ISMS).
