• Review of existing ISMS procedures and structures
• Comparing the existing management system with ISO 27001 / TISAX / KRITIS / B3S / NIS2 / DORA requirements
• Assessing the adequacy and effectiveness of technical and organizational measures
• Documentation and audit report
• Recommending and prioritizing measures
• Detailed management report
• Audit of the BCMS according to ISO 22301 and BSI Standard 200-4
• Assessing business impact analysis, emergency concept and recovery plans
• Reviewing the effectiveness of emergency tests and exercises
• Documenting findings in the audit report
• Recommending and prioritizing measures
• Auditing service providers and cloud vendors on-site or remotely
• Assessment according to ISO 27001, NIS2, DORA and contractual requirements
• Review of outsourcing agreements, SLAs and evidence
• Assessing supply chain risks
• Audit report with findings and follow-up of measures
• Preparing for certification and surveillance audits
• Review of management review, security objectives and metrics
• Assessing the effectiveness of the ISMS and continuous improvement
• Review of evidence for the management level
• Management report with prioritized recommendations