Whitesec ID
Core Service

Integrated Cyber Security & Compliance Services

A management system that is documented, lived, and ready for audit

  • ISO 27001
  • IT Governance
  • Risk Management
  • Compliance Framework

We build information security management systems from the ground up, or repair the one you already run. The work moves from gap analysis through control design and documentation to standing beside you during the certification audit.

What you receive

  • Gap analysis report and implementation roadmap
  • ISMS documentation: policies, procedures, forms
  • Risk register and Statement of Applicability
  • Internal audit report and management review
  • Certification audit support from start to finish
Context & Urgency

Why this matters now

Requests for security evidence no longer come from regulators alone. Prospective customers, partners, and insurers now routinely ask what management system you run before the relationship goes any further.

  • Compliance has become a commercial condition

    Corporate tenders and vendor onboarding frequently require an ISO 27001 certificate. Without one, the conversation stops before price is ever discussed.

  • The ISO 27001 control structure has changed

    The 2022 revision reorganised Annex A into 93 controls across four themes. The transition period from the 2013 version has closed, so certification now refers fully to the current release.

  • A certificate without practice has a short life

    Surveillance audits find controls that exist on paper but not in operation, and those turn into major nonconformities.

Signs your organisation needs this

  • Security questionnaires from prospects cannot be answered in full
  • Security policies exist, but evidence of them running is hard to collect
  • Risks are discussed in meetings yet never reach the risk register
  • The certificate is close to expiry and the surveillance audit is unprepared

Any one of these is reason enough to start the conversation early.

Scope

What we cover

  • ISO/IEC 27001 — Information Security

    Scope definition, risk assessment, Statement of Applicability, policies, and Annex A controls.

  • ISO/IEC 27701 — Information Privacy

    Extending your ISMS into a PIMS, aligned with Indonesia's Personal Data Protection Law.

  • ISO/IEC 42001 — AI Governance

    Governance for organisations putting artificial intelligence into production.

  • ISO 9001 — Quality Management

    Operational processes that stay consistent, measurable, and straightforward to audit.

  • IT Governance & Risk Management

    Governance structure, responsibility matrix, risk register, and control mechanisms.

  • Audit & Due Diligence Readiness

    Evidence prepared for regulator audits, internal audits, and partner due diligence.

How We Work

Clear stages, with no surprises along the way

Every stage has agreed deliverables, so progress is never in question.

  1. 01

    Gap Analysis

    Mapping where you stand today against the requirements of the standard.

  2. 02

    System Design

    Scope, policies, procedures, and controls matched to your risk profile.

  3. 03

    Implementation

    Rolling out controls alongside your internal team, training included.

  4. 04

    Internal Audit

    Testing control effectiveness and closing corrective actions before the external audit.

  5. 05

    Certification

    Support through Stage 1 and Stage 2 with the certification body.

Reference Basis

The standards and regulations we work from

Every recommendation traces back to the references below and can be verified independently.

  • ISO/IEC 27001:2022Requirements for an information security management system.
  • ISO/IEC 27002:2022Implementation guidance for the 93 Annex A controls.
  • ISO/IEC 27005Guidance on information security risk management.
  • ISO 31000:2018Organisational risk management framework.
  • Government Regulation No. 71 of 2019Obligations of electronic system operators.

Success indicators

Agreed upfront so the work is judged objectively rather than by impression.

  • Share of Annex A controls operating with evidence
  • Number of major nonconformities at internal audit
  • Time taken to produce evidence on request
  • Management review held on schedule
Glossary

Terms that come up in these discussions

The vocabulary you will meet in documents, reports, and conversations with auditors.

ISMS
Information Security Management System — the policies, processes, and controls managed systematically to protect organisational information.
Statement of Applicability
The document auditors work from, stating which controls are applied, which are excluded, and the reasoning behind each.
Risk Treatment Plan
The plan for handling risk, listing actions, owners, and deadlines for every risk that cannot be accepted.
Surveillance Audit
The periodic audit by the certification body confirming the system still operates between certification cycles.
Frequently Asked

The questions we hear most

Still unanswered? Send your question and our team will reply on a working day.

Ready to build stronger security?

Talk your organisation's needs through with our team. Free, and without obligation.