DRAFT - FOR REVIEW
Viewee ISO/IEC 27001 Programme Roadmap
From zero to certification-ready | Version 0.1 | 16 September 2026
Build a small, operating ISMS around the whole Viewee service, not a paperwork-only project. Allow 9-12 months from an agreed scope to a credible Stage 2 audit for a two-person team, assuming roughly 0.5-1 founder-day per week during build, 1-2 days per month during the evidence period, and short peaks around audit and remediation. Faster is possible, but rushing before Viewee has several months of operating evidence increases rework and audit risk.
Viewee is not certified today and should say "working towards ISO/IEC 27001 alignment", never "ISO compliant" or "certification-ready", until an accredited certification body has completed the process.
Proposed ISMS scope
The design, development, hosting, operation and support of Viewee's feedback-to-action SaaS for UK adult social care, including founders and contractors, production and non-production environments, marketing site, web application, API, source code and CI/CD, corporate endpoints and identity, customer support, and suppliers that process or can affect customer information.
Record physical and organisational boundaries, exclusions, interfaces and dependencies. Revisit the scope before certification if the architecture, team, offices or services change.
Roadmap
| Phase | Timing | Work and outputs | Typical founder effort |
|---|---|---|---|
| 0. Mobilise | Weeks 1-2 | Name ISMS sponsor and owner; approve scope; identify interested parties and legal/contract requirements; set document control and programme rhythm. | 2-4 days total |
| 1. Understand risk | Weeks 2-6 | Asset and data-flow registers; risk method; first risk register; treatment plan; objectives; initial Statement of Applicability. | 4-8 days total |
| 2. Close priority gaps | Months 2-5 | Policies and working controls for identity, suppliers, secure development, vulnerability handling, backups, logging, incidents, continuity, privacy, retention and support access. | 0.5-1 day/week |
| 3. Operate and evidence | Months 4-8 | Run access reviews, scans, restore tests, supplier reviews, incident exercise, metrics, change records, training and risk reviews. Retain evidence of actual use. | 1-2 days/month plus fixes |
| 4. Check and correct | Months 7-9 | Internal audit by someone sufficiently objective; founder management review; corrective actions, root causes and effectiveness checks. | 3-6 founder days plus auditor |
| 5. Certify | Months 9-12 | Select UKAS-accredited certification body; Stage 1 readiness/document review; close findings; Stage 2 implementation audit; resolve nonconformities. | 3-6 founder days plus audit |
| 6. Maintain | After certification | Objectives, metrics, risk reviews, internal audit, management review, corrective action and certification surveillance. | 1-2 days/month, with peaks |
Risk method and register
Define assets/processes, risk owners and confidentiality, integrity and availability impacts.
Use a simple 1-5 likelihood and 1-5 impact scale. Score inherent risk before controls and residual risk after controls.
Set written acceptance thresholds. Example: 1-4 accept locally; 5-9 owner treatment/acceptance; 10-15 founder approval and dated treatment; 16-25 immediate action or stop the activity. Validate thresholds against customer and legal duties.
Choose treatment: reduce, avoid, transfer or accept. Every treatment needs an owner, due date and evidence.
Review quarterly and after material changes, incidents, new suppliers or customer requirements.
| Minimum register fields | Example evidence |
|---|---|
| ID, asset/process, threat/event, vulnerability/cause, impact, owner, existing controls, inherent score, treatment, due date, residual score, acceptance, review date | Ticket, configuration export, scan, access review, test result, contract, meeting decision |
Statement of Applicability
Build the SoA from the risk treatment process and compare selected controls with every Annex A control. For each control record applicability, justification for inclusion or exclusion, implementation status, control owner and evidence link. The SoA is not a copied checklist. It must match Viewee's risks, scope and real operating controls.
Minimum ISMS evidence set
Scope, context and interested-party requirements; roles and approved information-security policy.
Risk method, register, treatment plan, residual-risk approvals and SoA.
Objectives and measures with owners and review results.
Asset/data-flow and supplier registers; DPIA/ROPA links where relevant.
Access, MFA, privileged/support access and periodic access-review evidence.
Secure development, change, environment separation, vulnerability and patch records.
Logging/alerting, incident plan and exercise; backup and restore test; continuity test.
Training/competence, document control, internal audit, management review and corrective-action records.
Internal audit and management review
The internal audit must test both conformity and effective operation across the full scope. The auditor must be objective and must not simply approve their own work. A specialist external internal auditor is sensible for a two-person team. Track findings to closure.
After the internal audit, founders should hold a minuted management review covering prior actions, context changes, interested parties, performance and metrics, audit results, objectives, incidents/nonconformities, risk and treatment status, resources, supplier issues and improvement decisions.
Certification stages
| Stage | What to expect | Go/no-go test |
|---|---|---|
| Choose certification body | Check the body's live UKAS accreditation and scope for ISO/IEC 27001. Get comparable quotes and audit-day assumptions. | Accreditation verified directly with UKAS. |
| Stage 1 | Readiness and documented-system review, scope confirmation and planning for Stage 2. | ISMS defined; required documents and at least one internal audit and management review complete. |
| Stage 2 | Audit of implementation and effectiveness using interviews and records across the scope. | Several months of coherent evidence; Stage 1 findings closed. |
| After certification | Surveillance audits and continual improvement through the certification cycle. | ISMS remains active between audits. |
Do now versus later
| Do now | Do later, when the product is operating |
|---|---|
| Scope; roles; context; obligations; registers; risk method and first assessment; SoA v0.1; policies tied to how Viewee actually works; supplier due diligence; secure architecture; document control. | Accumulate access reviews, tickets, scan/remediation history, backup restores, incident exercise, metrics and review cycles; independent testing; internal audit; management review; certification-body engagement. |
The existing Legal-folder compliance pack already identifies the core gaps: no formal scope, risk register, SoA, internal audit, management review or operating-evidence set. Reuse its ISO requirements tracker as the control/evidence index instead of creating a competing checklist.
First 30 days
Approve the proposed scope and assign the ISMS owner.
Create registers for interested parties/obligations, assets/data flows, suppliers, risks, controls/evidence and corrective actions.
Complete the first risk workshop and issue SoA v0.1.
Pick five priority evidence-producing controls: MFA/access review, vulnerability workflow, backup/restore, incident exercise and supplier review.
Book a three-month evidence checkpoint. Do not book certification dates yet.
