Multiple projects · 6 domains
A. Core GRC / Cybersecurity Governance Projects
Assurava helps organizations build strong cybersecurity governance foundations through ISMS implementation, policy and control governance, internal assurance, incident oversight, access governance, executive reporting, and GRC workflow enablement. These projects reflect our ability to strengthen governance, improve audit readiness, and support more effective security decision-making.

Enterprise ISMS Implementation and Maintenance Program

Frameworks: ISO 27001, ISO 27002, internal security policies, regulatory security requirements

What the project is
An enterprise-wide initiative to establish, operate, and continuously improve an Information Security Management System (ISMS) across business units, IT environments, and operational functions.

Project description
This project focuses on defining the ISMS scope, governance structure, policies, Statement of Applicability (SoA), risk treatment plans, and reporting mechanisms needed to manage information security systematically. It also includes coordinating control implementation with control owners, supporting certification readiness, and maintaining compliance through internal reviews, management reviews, and corrective actions.

ISO 27001:2013 to ISO 27001:2022 Transition Project

Frameworks: ISO 27001:2022, ISO 27002:2022

What the project is
A structured transition project to migrate an existing ISO 27001:2013-certified ISMS to ISO 27001:2022.

Project description
This project involves conducting a gap assessment between the 2013 and 2022 versions of the standard, updating policies and control documentation, revising the Statement of Applicability, and aligning governance processes to the new control structure. It also includes updating risk treatment documentation, internal audit criteria, and evidence repositories to support certification transition and surveillance audits.

Security Governance Framework and Policy Harmonization Project

Frameworks: ISO 27001, NIST CSF, internal governance standards

What the project is
A governance project to standardize, rationalize, and strengthen the organization's cybersecurity policy and control documentation framework.

Project description
The objective is to review all security policies, standards, procedures, and baselines; remove duplication and inconsistency; align documents to security frameworks and regulatory obligations; and define ownership, review cycles, exception handling, and approval workflows. The project creates a more coherent and auditable governance structure for information security documentation.

Internal Security Audit and Compliance Assurance Program

Frameworks: ISO 27001, internal audit standards, control assurance methodologies

What the project is
A structured internal audit and compliance assurance program for validating the design and effectiveness of cybersecurity controls.

Project description
This project establishes a rolling audit plan covering key control areas such as access control, asset management, incident management, backup and recovery, logging, monitoring, and supplier security. It includes development of audit workpapers, evidence review procedures, observation tracking, corrective action follow-up, and reporting of compliance status to management.

Privileged Access and Identity Governance Compliance Review

Frameworks: ISO 27001, IAM governance, access control standards

What the project is
A focused review of identity and access governance practices, especially privileged access management and administrative account control.

Project description
This project examines privileged accounts, shared accounts, joiner/mover/leaver controls, periodic access recertification, segregation of duties, and privileged session management. It identifies access-related control weaknesses, defines remediation actions with IAM and infrastructure teams, and strengthens governance over administrative access to critical systems.

Security Incident Governance and Post-Incident Corrective Action Program

Frameworks: ISO 27035, ISO 27001, incident response governance

What the project is
A governance improvement project to strengthen how the organization manages cyber incidents, lessons learned, and corrective actions after incidents occur.

Project description
This project reviews incident classification, escalation, reporting, investigation, and closure procedures. It also establishes a structured post-incident review process to capture root causes, track corrective actions, identify recurring control failures, and feed lessons learned back into risk management, control improvements, and executive reporting.

Security Metrics, KRIs, KPIs, and Executive Reporting Program

Frameworks: GRC governance, ISO performance evaluation, enterprise risk reporting

What the project is
A management reporting program for measuring and communicating cybersecurity risk, compliance performance, control health, and remediation progress.

Project description
This project defines a cybersecurity KPI/KRI framework and develops dashboards and reporting packs for executives, risk committees, and audit stakeholders. Metrics typically include open risks, overdue remediation actions, audit findings, exceptions, incident trends, third-party risk exposure, and compliance status, helping leadership make informed risk-based decisions.

GRC Tool Implementation / Risk Workflow Automation Project

Frameworks: GRC tooling, workflow automation, audit and issue management

What the project is
A project to implement or optimize a GRC platform for managing risks, controls, audits, issues, compliance obligations, and exception workflows.

Project description
This initiative configures workflows for risk intake, risk assessments, control testing, audit findings, issue remediation, and policy exceptions. It often includes migrating spreadsheet-based registers into a centralized platform, designing dashboards, automating reminders and escalations, and improving traceability across the end-to-end GRC lifecycle.

B. Telecom-Specific GRC / Cybersecurity Projects
Assurava supports high-availability and infrastructure-intensive environments where cybersecurity must protect critical services, network resilience, and operational continuity. Our work in network risk governance, disaster recovery oversight, and secure technology onboarding helps organizations strengthen resilience across complex operational environments.

Network Risk Assessment and Security Governance Project

Frameworks: ISO 27005, NIST CSF, infrastructure security governance

What the project is
A targeted risk assessment and governance project focused on network infrastructure, connectivity services, and critical operational platforms.

Project description
This project identifies cyber and operational risks across network environments such as core infrastructure, gateways, remote access paths, network management systems, and legacy platforms. It evaluates risks such as outages, unauthorized access, weak segmentation, insecure configurations, and vendor remote access exposure, then develops treatment plans in coordination with infrastructure and operations teams.

Critical Service Resilience and Disaster Recovery Governance Project

Frameworks: ISO 22301, ISO 27001, business continuity and disaster recovery practices

What the project is
A governance and assurance project aimed at strengthening resilience, business continuity, and disaster recovery readiness for critical services and supporting technology environments.

Project description
The project reviews business impact analyses, recovery objectives, disaster recovery architecture, backup and restore controls, failover arrangements, and DR testing programs. It also coordinates tabletop exercises or simulations, validates remediation of identified gaps, and improves governance over continuity planning and service recovery capabilities.

Secure Procurement and Solution Security Review Project

Frameworks: ISO 27001, secure architecture governance, risk-based onboarding controls

What the project is
A security governance project that embeds cybersecurity review into procurement, solution onboarding, and technology change processes.

Project description
The project introduces security review checkpoints before new applications, platforms, cloud services, or managed services are approved for production use. It defines baseline security requirements, architecture review criteria, risk acceptance processes, and mandatory controls that must be satisfied before go-live, helping ensure secure-by-design adoption of new technologies.

C. Compliance / Regulatory / Control Assurance Projects
Assurava helps organizations turn regulatory and framework requirements into practical compliance and control assurance programs. Through control mapping, regulatory alignment, third-party assurance, and compliance governance, we help clients improve audit readiness, strengthen accountability, and build sustainable compliance practices.

Regulatory Cybersecurity Compliance Program for Critical Controls

Frameworks: ISO 27001, national cybersecurity regulations, sector-specific security requirements

What the project is
A formal compliance initiative to assess, implement, and evidence cybersecurity controls required by applicable regulatory or supervisory frameworks.

Project description
The project maps organizational policies, standards, and controls to regulatory requirements, identifies gaps, coordinates evidence collection, and tracks remediation plans. It is designed to provide management with visibility into compliance posture and ensure that mandatory security obligations are translated into actionable control implementation and assurance activities.

Multi-Framework Control Mapping and Unified Compliance Repository

Frameworks: ISO 27001, ISO 27005, NIST CSF, COBIT, CIS Controls, regulatory frameworks

What the project is
A control architecture project to create a single unified control library that maps one set of controls to multiple frameworks and audit requirements.

Project description
This project reduces duplication across audits, compliance assessments, and evidence requests by building a cross-framework mapping repository. It defines common control owners, consolidates evidence references, aligns control statements across standards, and enables integrated assurance reporting across multiple compliance obligations.

Third-Party / Vendor Security Risk Management Program

Frameworks: ISO 27001, ISO 27036, third-party risk governance

What the project is
A vendor risk management program designed to assess and monitor the cybersecurity risk posed by suppliers, outsourcing providers, technology partners, and managed service vendors.

Project description
This project establishes vendor risk classification criteria, pre-onboarding and renewal assessments, due diligence questionnaires, contract security requirements, and remediation tracking. It covers issues such as data access, hosting arrangements, subcontracting, incident notification clauses, and vendor control maturity, ensuring that third-party risks are governed consistently.

D. ISO 27005-Specific Risk Projects
Assurava enables organizations to build risk-driven cybersecurity programs through enterprise risk management, ISO 27005-based methodology design, critical asset risk assessment, and risk treatment governance. These projects demonstrate our ability to help clients identify, prioritize, and manage cyber risk in a structured and business-aligned way.

Enterprise Cybersecurity Risk Management Program

Frameworks: ISO 27005, NIST CSF, NIST SP 800-53, COBIT

What the project is
A centralized cybersecurity risk management program designed to identify, assess, treat, monitor, and report cyber risks across the enterprise.

Project description
This project establishes the organization's risk methodology, including impact and likelihood scoring, risk acceptance criteria, ownership, treatment tracking, and residual risk monitoring. It covers risk assessments for business applications, infrastructure, internet-facing systems, cloud services, and third parties, and provides governance reporting to management and risk committees.

ISO 27005 Risk Methodology Standardization Project

Frameworks: ISO 27005, enterprise risk governance

What the project is
A methodology design project to standardize how information security risk assessments are performed across the organization.

Project description
This project defines a common risk assessment model, including asset-based and scenario-based assessment approaches, scoring scales, impact categories, inherent vs residual risk treatment, acceptance thresholds, and review cycles. Its purpose is to ensure that different departments assess cyber risks using a consistent and defensible methodology.

Critical Asset and Crown Jewels Risk Assessment Project

Frameworks: ISO 27005, critical asset protection, business impact and risk assessment

What the project is
A focused risk assessment project to identify the organization's most critical information assets, systems, and services and evaluate the cyber risks associated with them.

Project description
This project identifies crown jewel assets, assesses their confidentiality, integrity, and availability requirements, evaluates key threats and vulnerabilities, and prioritizes treatment actions based on business criticality. It is often used to support executive prioritization of cybersecurity investments and resilience planning.

Risk Treatment and Risk Acceptance Governance Project

Frameworks: ISO 27005, enterprise risk governance, issue remediation governance

What the project is
A governance project designed to ensure that identified cyber risks are formally owned, treated, escalated, accepted, or monitored in a controlled and auditable way.

Project description
The project establishes workflows for assigning risk owners, documenting treatment plans, tracking deadlines, escalating overdue actions, and approving risk acceptance or exceptions. It improves accountability for remediation and creates clear governance around residual risk decisions and management sign-off.

E. ISO 42001 / AI Governance Projects
Assurava helps organizations extend governance into AI, responsible AI, and AI management systems. Through AI governance framework design, AI risk oversight, and ISO 42001 readiness, we support clients in adopting AI with stronger oversight, clearer accountability, and better alignment to emerging standards and expectations.

AI Governance Framework Design for Enterprise AI Use Cases

Frameworks: ISO/IEC 42001, NIST AI RMF, ISO 23894, privacy and security governance

What the project is
An enterprise AI governance project to define how artificial intelligence use cases are approved, governed, monitored, and controlled across the organization.

Project description
This project creates the policies, roles, review processes, and lifecycle checkpoints needed to govern AI systems such as chatbots, predictive analytics, automation tools, fraud detection models, and other AI-enabled solutions. It includes AI use case classification, accountability structures, integration with risk management, and oversight mechanisms for responsible AI adoption.

ISO 42001 AI Management System Readiness / Gap Assessment

Frameworks: ISO 42001

What the project is
A readiness and gap assessment project to evaluate whether the organization is prepared to implement an AI Management System (AIMS) aligned with ISO 42001.

Project description
This project reviews existing AI initiatives, governance practices, roles, policies, risk controls, monitoring mechanisms, and human oversight arrangements against ISO 42001 requirements. It identifies capability gaps, defines a target-state governance model, and produces a phased roadmap for AI governance implementation and future certification readiness.

F. EU Regulatory & Sector-Specific Compliance Projects
Assurava helps organizations navigate the evolving European regulatory landscape with practical compliance programs for DORA, NIS2, and other sector-specific requirements. Our work bridges the gap between regulatory mandates and operational reality, ensuring that financial entities, critical infrastructure operators, and essential service providers meet their obligations with confidence and efficiency.

DORA (Digital Operational Resilience Act) Readiness and Implementation Program

Frameworks: DORA (EU Regulation 2022/2554), ISO 27001, ICT risk management frameworks, EBA/ESMA/EIOPA regulatory technical standards

What the project is
A comprehensive readiness and implementation program to help financial entities and their critical ICT service providers align with the EU Digital Operational Resilience Act (DORA) requirements.

Project description
This project establishes a structured approach to DORA compliance across five core pillars: ICT risk management, incident reporting, digital operational resilience testing, third-party risk oversight, and information sharing. It includes mapping existing controls to DORA requirements, designing ICT risk management frameworks with clear governance and accountability structures, establishing incident classification and reporting protocols aligned with ESMA/EBA/EIOPA guidelines, implementing resilience testing programs (including threat-led penetration testing and scenario-based testing), developing third-party ICT provider oversight mechanisms with comprehensive due diligence frameworks, and creating governance structures for ongoing compliance monitoring and reporting to regulatory authorities. The project also includes remediation planning, evidence collection, and readiness validation to ensure organizations meet regulatory deadlines with confidence.

NIS2 Directive Readiness and Governance Uplift Program

Frameworks: NIS2 Directive (EU 2022/2555), ISO 27001, NIST CSF, national implementing legislation, sector-specific security requirements

What the project is
A governance and compliance program designed to help organizations subject to the NIS2 Directive interpret requirements, enhance security governance, and build incident response capabilities for critical infrastructure and essential services.

Project description
This project focuses on implementing the expanded NIS2 Directive requirements across essential and important entities. It begins with applicability assessment and gap analysis against the directive's requirements, followed by governance structure design including management body accountability frameworks, executive-level security responsibilities, and oversight mechanisms. The project establishes incident response and reporting capabilities aligned with CSIRT requirements (including 24-hour early warning and 72-hour notification timelines), strengthens supply chain security through vendor oversight programs with contractual security requirements, implements continuous compliance monitoring through established KPIs and reporting cadences, and establishes security training and awareness programs for personnel. It also includes cross-framework mapping with ISO 27001 and NIST CSF to leverage existing controls, reduce duplication, and create an integrated security governance model that adapts to evolving national implementing legislation.

Ready to start your compliance journey?

Book a free consultation and let's explore how we can support your organization's governance, risk, and compliance journey.

No obligation · 30-minute strategy session