Agree
Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.
Govern / New Zealand
Aegentra helps New Zealand organisations plan and implement an information security management system around their services, information, risks and responsibilities. We connect management decisions with operating controls and evidence, not just a library of policies.
Start with the boundary
For organisations responding to customer assurance requirements, defining a first ISMS or bringing an existing system into day-to-day operation.
Aegentra provides consulting support, not an organisational ISO certificate. Certification is a separate decision by an independent certification body. Neither a pass nor a fixed certification date is guaranteed.
What the engagement can produce
Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.
How we work
Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.
Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.
Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.
Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.
We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.
An illustrative starting point
Fictional example to explain the service, not a New Zealand client case study or a promised outcome.
A service provider has a customer deadline but no agreed certification boundary. The first useful decision is which services and supporting systems the ISMS covers. Buying more templates does not resolve that boundary.
Before you begin
Yes. A scoped review can distinguish useful existing material from gaps in operation, ownership and evidence. We do not assume you need to replace everything. The starting point is the actual ISMS boundary and what the records demonstrate.
The agreed scope can include legal entity, services, locations and information in the ISMS boundary; risk assessment, treatment decisions and control applicability; responsibilities, policies and evidence of operation; management review, improvement and preparation for independent assessment. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.
Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.
We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.
Bring answers to these starting questions: What does the customer require: a certificate, a control response or an audit report? Which entity and services must be in scope? Who can approve risk treatment and allocate implementation resources? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.
Reference points
Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.
Discuss your requirement
Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.