VITI Security
We do the security engineering, not the audit or the legal work. VITI Security implements and tests the technical security controls these frameworks require - access control, encryption, logging and monitoring, vulnerability management, and penetration testing. The certification or attestation is issued by an independent, accredited auditor or CPA firm that you retain; formal policy authoring, legal review, and Data Protection Officer duties sit with your auditor and privacy counsel, not with us. We have no partnership, referral fee, or kickback with any certifying body - you pick them, and we make the technical controls pass.

Service · ISO 27001 (technical controls)

ISO 27001: we build the technical controls.

An ISO 27001 ISMS has a management-system half (policies, risk methodology, the Statement of Applicability) and a technical-controls half. We do the technical half - the Annex A technological controls, a security gap assessment, and the testing that proves they hold. The certificate is issued by an accredited body you retain; we are not a certification body and take no referral fee.

What we do

Which ISO 27001 Annex A controls do we implement?

The engineering half of an ISMS - the controls an auditor actually inspects on the technical side.

Technical gap analysis

Current-state assessment against the technological Annex A controls (ISO 27001:2022). Output: a remediation backlog ranked by risk and effort.

Technical risk input

Asset inventory and threat modeling on the systems side, feeding the risk register your ISMS needs. The formal risk methodology + Statement of Applicability sit with your GRC lead; we supply the technical reality.

Control implementation

MFA, SSO, encryption in transit and at rest, centralized logging and monitoring, change management, and a secure SDLC.

Vulnerability management & VAPT

Penetration testing plus continuous scanning (Vexta) - the technical vulnerability-management evidence an auditor expects to see operating.

Control documentation

Clear write-ups of the technical controls and how they map to Annex A, so your auditor and GRC lead can slot them into the ISMS.

Technical auditor support

We answer the security-control questions and help show the technical evidence during stage-1 and stage-2 fieldwork, alongside the certifier you retain.

What we own vs. what stays with you

Annex A
Technical controls we implement + test
VAPT
Included - we prove the controls hold
Yours
You keep the certifier + the ISMS; we take no referral fee

How we scope it

How do we scope the ISO 27001 technical work?

Sized to your current security maturity after a short scoping call.

01

Assess

Technical gap analysis against the technological Annex A controls. You get a ranked control backlog.

02

Implement

We build and harden the technical controls - access, encryption, logging/monitoring, vulnerability management, secure SDLC.

03

Test

Penetration testing and scanning to confirm the controls hold and to produce technical evidence.

04

Support fieldwork

We stand alongside you on the technical questions while your chosen accredited body runs stage 1 and stage 2.

ISO 27001 FAQ

Do you do the audit, or issue the certificate?
Neither. The certificate has to be issued by an accredited certification body (UKAS, NABCB, ANAB, etc.). We do not issue certificates and have no partnership, referral fee, or kickback with any of them. You pick the certifier; we do the technical security work and sit alongside you on the security questions during fieldwork.
What exactly do you do vs. not do?
We do: the technical/technological Annex A controls, a security gap assessment, penetration testing, and clear documentation of those controls. We do not: run your ISMS management system, author the full policy framework and Statement of Applicability, or act as your certification body. The management-system and policy work sits with you or a dedicated GRC/ISMS consultant; the certificate sits with an accredited body.
What does it cost?
The technical-controls work is scoped per engagement after a short call, based on your current maturity - we quote a fixed price before we start. The certification body's audit and surveillance fees are separate and paid directly to them.
How does this relate to SOC 2?
The technical security controls overlap heavily between ISO 27001 and SOC 2, so if you are pursuing both, the technical work we do feeds both. The attestation/certificate for each is still issued by its respective independent body.

ISO 27001 on your roadmap?

Let's scope the technical-controls work. The ISMS and the certificate stay with you and your accredited body - we make the technical side solid.