Management statement available today, certification not yet booked

Our ISO 27001 position, and what we can give you now

We do not hold an ISO 27001 certificate. Rather than leave your diligence team with nothing, we issue a signed management statement on our information security management system, an extract of the statement of applicability with our own control reference and evidence against each Annex A area, the written risk method we apply, and a walkthrough where your team names the clause and we show what backs it, including the parts still being built.

18

Annex A mapped controls operating

21

Mapped controls in the register

50 percent

Management system artifacts complete

Available on request today

  • Signed management statement on the management system

    A letter signed by the chief executive setting out the scope of the management system, the risk method applied, the Annex A controls we operate, the management system artifacts still being built, and the date of the last review.

    It is not a certificate and it is not an accredited certification body's finding. It is management's own statement, and it says so in its opening paragraph.

    Available immediately on request, dated the day it is issued.

  • Statement of applicability extract

    The Annex A control areas relevant to your engagement, each with whether it applies, our own control reference, the owner, the evidence, and the current status.

    It is not a certified statement of applicability reviewed by a certification body.

    Available immediately on request, scoped to your engagement.

  • Risk assessment and treatment method

    The written method by which we score confidentiality, integrity, and availability risk, the acceptance thresholds, who signs an accepted risk, and a worked example of the method applied.

    It is not a copy of our internal risk register, which holds our own exposures.

    Available within two working days of a request.

  • Management system evidence walkthrough

    A scheduled session where your security or procurement team names clauses or Annex A controls and we show the dated evidence behind them, including anything that fails.

    It is not a stage one audit, and we do not present it as one.

    Available within five working days of a request.

  • Completed questionnaire against ISO 27001

    Your own diligence questionnaire returned complete, answered only from the register and the management system record, with anything we do not hold marked as not held rather than left blank.

    It is not a claim of certification in a different format.

    Returned within five working days for a standard questionnaire.

Not available, and we will not imply otherwise

  • ISO 27001 certificate. It is not something we hold today, and we will not describe our own documents as one. Not available. No stage one audit has been booked. We will tell you the honest position on the day you ask.
  • Stage one or stage two audit report. It is not a document any party other than a certification body can produce. Not available until the certification audits are complete.

We hold no ISO 27001 certificate and have not yet booked a stage one audit. We state that plainly in proposals and in questionnaire answers, and we offer the register, the risk method, and the evidence instead.

What the management statement says

The letter is signed by Cleandra LeSane, Chief Executive Officer, Dephiant Consulting Inc. and reissued with each register review. These are its sections, in the order they appear.

Purpose and limitations of this statement
This document is a statement by the management of Dephiant Consulting Inc. about its information security management system. It is not a certificate, it is not an accredited certification body's finding, and it is not a stage one or stage two audit report. Dephiant Consulting Inc. does not hold an ISO 27001 certificate, a SOC 2 Type 1 or Type 2 report, a CMMC certification, or a FedRAMP authorization. Any party relying on this document should read it as management's own assertion, supported by dated evidence that is available for inspection, and nothing more than that.
Scope of the management system
The information security management system covers the advisory, assessment, and managed advisory services we deliver to clients, the people who deliver them, and the systems that hold client material. It is a single location and a single legal entity, which keeps the management system proportionate to the size of the firm.
Risk assessment and treatment method
Risk is assessed against confidentiality, integrity, and availability for each information asset, using the same register and the same scoring method we run for clients. Treatment decisions are recorded with an owner and a review date, and accepted risk is signed by the CEO rather than absorbed quietly.
Statement of applicability
The statement of applicability lists every Annex A control, whether it applies, the justification either way, and the control reference in our own register. A control marked not applicable carries a written reason, because an auditor will test that reason before accepting it.
Management assertion
Management asserts that the controls described in the attached extract are documented, assigned to a named owner, and operating as described, except for those recorded with a status of in progress or planned, which are listed separately with the window in which they are scheduled. Management further asserts that the management system artifacts listed in this statement are at the state recorded against each one, currently 50 percent complete by artifact, and that We operate a documented control set aligned to SOC 2 trust services criteria, ISO 27001 Annex A, and the NIST SP 800-171 practices that CMMC Level 2 assesses. We hold no SOC 2 report and no CMMC certification, because those come from an independent auditor or an authorized assessor. What we do hold is a register of controls, named owners, and dated evidence, which we review every quarter and will walk a client or their auditor through on request.
How the register and the management system are maintained
The register is reviewed on this cadence: Every quarter, with three controls tested in depth each cycle so every control is tested at least once a year. Client security questionnaires and vendor diligence requests are answered from this register only. Nobody answers a diligence question from memory. Where the register and any public statement disagree, the public statement is corrected, not the register.
Relationship to our SOC 2 work
The control build serves both frameworks. The SOC 2 examination tests control design and operation over a period. ISO tests whether a management system governs those controls and improves them. Running them together saves roughly a third of the effort compared with running them apart.
Artifacts not yet complete
Management system artifacts recorded as in progress or not started are listed in the attached extract with their clause and the proof that will close them. They are disclosed here rather than omitted, because a client discovering them later is worse for both parties.
Client information handling
Client material is held in approved stores only, separated by client, retained only as long as the engagement and the agreed retention period require, and returned or destroyed on request with a record of the destruction. Subcontractors are assessed and bound to the same obligations before they touch client material.
Certification path
Certification requires a stage one audit of the documented management system, then a stage two audit of it operating, both performed by an accredited certification body. A surveillance audit follows annually, and recertification every three years. We treat the annual surveillance cost as part of the decision, not a surprise after it.
What we will do on request
We will provide the statement of applicability extract relevant to your engagement, the written risk method, a walkthrough of the evidence behind any clause or control you name, and a completed diligence questionnaire answered from the record. Where we do not hold something you require, we say so in writing.
Signature
Signed for and on behalf of Dephiant Consulting Inc. by Cleandra LeSane, Chief Executive Officer, Dephiant Consulting Inc.. This statement is reissued every quarter with the register review, and on request where a procurement needs a letter dated inside a stated window.

Management system artifacts and their state

ISO 27001 asks for a management system, not only a set of controls. This is every artifact it requires, the clause behind it, and whether we hold it today.

ArtifactClauseProofState
Management system scope statementClause 4.3Approved and dated scope statement naming services, people, locations, and systems.done
Information security policy signed by top managementClause 5.2Signed policy with a review date and evidence of communication to everyone in scope.in progress
Risk assessment and treatment methodClause 6.1.2Documented method plus a completed assessment showing the method applied.done
Statement of applicabilityClause 6.1.3All Annex A controls listed with applicability, justification, and register reference.in progress
Risk treatment plan with owners and datesClause 6.1.3Treatment plan extracted from the risk register with owners, dates, and status.in progress
Security objectives and how they are measuredClause 6.2Objectives with a measure, a target, a source, and at least one recorded measurement.in progress
Competence and awareness recordsClauses 7.2 and 7.3Training records, the role skill matrix, and awareness campaign completion.done
Documented information controlClause 7.5Document register with version, owner, approval date, and review date.in progress
Operational control evidenceClause 8.1Evidence log covering at least three months for every applicable control.in progress
Monitoring and measurement resultsClause 9.1Measurement records and the decisions they drove.in progress
Internal audit program and first audit reportClause 9.2Audit program, audit plan, report, and nonconformity records.not started
Management review minutesClause 9.3Minutes showing each required input, the decisions taken, and resources committed.not started
Nonconformity and corrective action recordsClause 10.2Corrective action records with root cause, correction, and verified closure.not started

10 of these artifacts are not yet finished. They are listed above with their clause rather than hidden, and the work that closes them sits on the readiness plan with an owner and a window.

Annex A mapped controls

These are the controls in our register that carry an ISO 27001 mapping. The extract you receive is scoped to your engagement and carries the evidence reference for each row.

ReferenceControlEvidenceStatus
GOV-01The CEO holds accountability for security. The compliance lane owns this register and reports it at the quarterly management review.Quarterly management review record with the register attached.in place
GOV-02Every team member completes onboarding training before client work, then annual mandatory training, recorded with evidence. A skill matrix tracks capability by role.Training completion records and the role skill matrix.in place
GOV-03Information handling rules cover classification, client separation, storage locations, and what never leaves the approved store. Read and confirmed at onboarding.Signed confirmation per team member, held in the people record.in place
RSK-01We keep our own risk register on the same standard we apply to clients, reviewed quarterly, with accepted risks signed and given a review date.Internal risk register with dated review entries and signed acceptances.in place
RSK-02Every supplier and subcontractor is tiered, assessed at the tier their access requires, contracted with flow down terms, and reassessed on the set interval.Vendor register with tiers, assessment dates, and signed agreements.in place
ACC-01Every account, ours or in a client environment, is requested and approved on the access form, granted at the lowest level that works, and recorded with a removal date where it is time boxed.Access register with approvals, grant dates, and removal confirmations.in place
ACC-02Multi factor authentication is enforced on all company accounts and on every client system where the client permits it. Exceptions are recorded with a reason and a date.Authentication policy enforcement report and the exception list.in place
ACC-03We review access to our own systems quarterly, and we remove client access at engagement close and on the day a team member departs, with timestamps recorded.Quarterly access review records and dated exit records.in place
DAT-01Client material lives only in the approved store, in a folder restricted to assigned staff, with named expiring shares. Confidential and restricted material never travels as an email attachment.Store configuration record, share settings, and the engagement folder access list.in place
DAT-02Retention is agreed at kickoff, applied at close out, and evidenced by a destruction or return record verified by a second person.Data return and destruction records, kept for seven years.in place
DAT-03We maintain our own processing record, screen new processing activities before they go live, and run a full impact assessment when screening calls for one.Processing record and dated screening decisions, including the not required ones.in place
CHG-01Website and platform changes are reviewed before release, and client facing documents pass an independent quality review by someone other than the author.Release records and deliverable review records naming the reviewer.in place
MON-01Administrative activity and sign in events on our own systems are logged and alerted, with alerts routed to a named owner rather than to a shared inbox nobody reads.Alert configuration record and a sample of investigated alerts.in progress (Months 2 to 4)
VUL-01Our own platform and dependencies are scanned, findings are triaged by exposure, and closure requires a clean re-scan rather than a statement that it is fixed.Scan records, remediation dates, and verification re-scans.in place
IRP-01We run the same incident procedure internally that we run for clients: a timestamped record from the first minute, a named lead, and a lessons review within ten working days.Incident records with timelines, and lessons reviews with owned actions.in place
IRP-02We run one internal tabletop exercise each year and record the gaps as owned actions with dates.Exercise report with the action list and completion dates.in progress (Months 4 to 6)
IRP-03Recovery objectives are written down for the systems we depend on, and a restore is tested annually with the measured time recorded against the objective.Continuity test record showing measured recovery times.in progress (Months 4 to 6)
AUT-01No scanning, enumeration, or exploitation happens without a signed authorization letter, signed rules of engagement, and a completed go or no go checklist on the morning of testing.Signed authorization file and completed go or no go checklists.in place
AUT-02Findings and captured evidence live in the restricted findings store only, with the minimum data needed, personal data redacted, and no live customer records copied out.Store access list and the evidence handling note on each finding record.in place
CLI-01Each client has a portal holding their pack, their briefings, and the security commitments that apply to them, plus a weekly status report during active delivery.Portal records and filed status reports.in place
CLI-02Satisfaction surveys run at close out and at each quarterly review. Scores below the threshold get contact from the engagement lead within two business days and a written corrective action.Survey records with corrective actions and closure dates.in place

How certification would happen

Certification requires a stage one audit of the documented management system, then a stage two audit of it operating, both performed by an accredited certification body. A surveillance audit follows annually, and recertification every three years. We treat the annual surveillance cost as part of the decision, not a surprise after it.

The control build serves both frameworks. The SOC 2 examination tests control design and operation over a period. ISO tests whether a management system governs those controls and improves them. Running them together saves roughly a third of the effort compared with running them apart.

Request the ISO 27001 pack

Tell us who you are and what your diligence process needs. We will send what we hold and state plainly what we do not.

What would you like