AegentraNew Zealand

Govern / New Zealand

ISO 27001 implementation

Aegentra helps New Zealand organisations plan and implement an information security management system around their services, information, risks and responsibilities. We connect management decisions with operating controls and evidence, not just a library of policies.

On this page

Start with the boundary

Define the work that is needed.

For organisations responding to customer assurance requirements, defining a first ISMS or bringing an existing system into day-to-day operation.

  • Legal entity, services, locations and information in the ISMS boundary
  • Risk assessment, treatment decisions and control applicability
  • Responsibilities, policies and evidence of operation
  • Management review, improvement and preparation for independent assessment

Keep the responsibilities distinct

Aegentra provides consulting support, not an organisational ISO certificate. Certification is a separate decision by an independent certification body. Neither a pass nor a fixed certification date is guaranteed.

What the engagement can produce

Useful outputs, agreed in advance.

  • An agreed ISMS scope and implementation roadmap
  • A risk and control workstream with accountable owners
  • Prioritised documents, records and operating evidence
  • A readiness view identifying gaps and next actions

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How we work

From evidence to a practical next step.

Agree

Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.

Examine

Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.

Act or report

Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.

Verify and hand over

Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

An illustrative starting point

What a useful first decision looks like.

Fictional example to explain the service, not a New Zealand client case study or a promised outcome.

A service provider has a customer deadline but no agreed certification boundary. The first useful decision is which services and supporting systems the ISMS covers. Buying more templates does not resolve that boundary.

Questions for the first discussion

  • What does the customer require: a certificate, a control response or an audit report?
  • Which entity and services must be in scope?
  • Who can approve risk treatment and allocate implementation resources?

Before you begin

Your questions, answered.

Can you help if we already have ISO 27001 documents?

Yes. A scoped review can distinguish useful existing material from gaps in operation, ownership and evidence. We do not assume you need to replace everything. The starting point is the actual ISMS boundary and what the records demonstrate.

What can be included in iso 27001 implementation?

The agreed scope can include legal entity, services, locations and information in the ISMS boundary; risk assessment, treatment decisions and control applicability; responsibilities, policies and evidence of operation; management review, improvement and preparation for independent assessment. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.

How much does this service cost?

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How do you deliver the work in New Zealand?

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

What should we provide before a proposal?

Bring answers to these starting questions: What does the customer require: a certificate, a control response or an audit report? Which entity and services must be in scope? Who can approve risk treatment and allocate implementation resources? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.

Reference points

Check the underlying guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss your requirement

Start with your business.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.