ISO/IEC 27001 IMPLEMENTATION

ISO 27001 doesn't fail on paperwork. It fails on people.

Culture IT builds information security management systems that pass certification — and habits that hold up after the auditor leaves.

Culture IT

Four themes. Ninety-three controls.
One culture running through all of them.

ISO/IEC 27001:2022 groups every Annex A control into four themes. Only one is explicitly about people — but people execute the other three.

CLAUSE A.5
Organizational
37 controls — policy owners, roles, supplier rules
CLAUSE A.6
People
8 controls — screening, training, disciplinary process
CLAUSE A.7
Physical
14 controls — site access, clear desk, equipment
CLAUSE A.8
Technological
34 controls — access, logging, malware, backups

What we actually deliver

Each of these six stands alone if you need it to, but they're built to interlock into a single ISMS your team can run without us.

01

Gap Assessment & Roadmap

We map your current controls against Annex A and hand you a prioritised, resourced plan to close the gaps — not a 200-page audit nobody reads.

02

Risk Assessment & SoA

A risk methodology your team can repeat next year without us, and a Statement of Applicability that reflects real decisions, not copy-paste justifications.

03

ISMS Documentation & Policy Build

Policies written in language your staff will actually follow, structured so document control doesn't become its own second job.

04

Security Culture & Awareness Training

Role-specific ISMS user education, phishing simulations, and reporting channels designed so people flag incidents instead of hiding them.

05

Internal Audit & Management Review

Independent internal audits and management review cycles that catch drift before your certification body does.

06

Certification & Surveillance Support

We sit alongside you through Stage 1, Stage 2, and every surveillance audit after — no surprises, no scrambling.

The cycle the standard already asks for

ISO 27001 runs on Plan–Do–Check–Act. Most consultancies handle Plan and Do, then leave. We're built around Check and Act — where culture actually forms.

Plan Do Check Act
P

Plan

Scope, risk assessment, Statement of Applicability, policy drafts, and a baseline read on how security actually feels to your staff today.

D

Do

Controls go live, ownership is assigned by name, and training is built for the role people do — not a generic annual module.

C

Check

Internal audit, phishing metrics, incident-reporting rates, and management review — measured against behaviour, not just documents.

A

Act

Nonconformities closed, training refreshed based on what actually happened, and the ISMS adjusted before the next surveillance audit.

Compliance versus culture

"Passing the audit is not the same as being secure."

— why we're called back in after a breach at a certified organisation
Compliance-only
Policy signed once, at induction, and never referenced again
Incidents go unreported because reporting feels like admitting blame
Awareness training is an annual slideshow with a quiz at the end
Security is "IT's job"
The Statement of Applicability is written to satisfy the auditor
Culture-based
Policy shows up in how meetings, onboarding, and reviews actually run
Incidents are reported early because reporting is treated as routine, not failure
Training is role-specific and reinforced through the year, not once
Every process owner carries a security responsibility they can name
The Statement of Applicability reflects decisions your team actually made

Built by people who've sat on both sides of the audit table

Culture IT was founded on a simple observation: most failed ISO 27001 programs weren't missing controls — they were missing buy-in. We work in-house alongside your team rather than handing over a binder and disappearing, because a management system only holds up if the people running it understand why it exists.

We work with small to medium businesses, government, and mining organisations, taking on a limited number of implementations at a time so every engagement gets direct attention through Stage 1, Stage 2, and beyond.

  • Sami Anderson
    CYBER SECURITY DIRECTOR
  • Catalina Anderson
    MARKETING DIRECTOR
  • ISO/IEC 27001 ISMS Implementation & Awareness Training
    CORE FOCUS

Start with a readiness call

Twenty minutes, no obligation. We'll tell you honestly whether you're ready to start — or what to fix first.

Thanks — that's landed with us. We'll be in touch soon.
Email
contact@cultureit.com.au
Postal address
PO Box 40, Forrestfield WA 6058
Focus
ISO 27001 ISMS implementation & user education / awareness training