Policies and procedures
The documented backbone: information security and acceptable use policies, access control and data retention procedures, and the incident response plan.
Audit-ready evidence, produced as a by-product of doing the work and recording it as you go, then kept current between assessments. When a regulator, insurer or prime contractor asks how you protect data, the proof is already in order. From a team certified for ISO 27001 by a UKAS-accredited certification body.
Assurance is the ongoing work of producing and maintaining the evidence that your controls are in place and working, not a separate project you start when an audit looms. We capture the trail continuously, package it the way assessors want it, and keep it current, so an audit becomes a matter of producing a pack.
Auditors ask for specific things. We make sure each one exists, is current, and is ready to hand over.
The documented backbone: information security and acceptable use policies, access control and data retention procedures, and the incident response plan.
Logging, monitoring and change records, retained so the trail is there when an assessor asks. The difference between saying a control works and showing it has been working.
The state of your systems, captured as evidence: hardening, firewall rules, multi factor authentication and patch status, recorded so an auditor can verify what is in place rather than what is claimed.
The certificates, assessment records and training logs that show your obligations are met, mapped to whichever standard applies, from Cyber Essentials to ISO 27001 to a sector toolkit.
A certificate is a snapshot: it says your controls were in good order on the day you were assessed. Systems change, people come and go, and threats move on, so a control that was sound in March can drift by September. Assurance keeps the picture true between snapshots.
For a standard like ISO 27001 this is built in. You keep the management system alive with internal audits, management reviews and surveillance audits between full recertifications. The same logic applies where a standard does not formally require it: evidence is only worth having if it reflects reality, and reality keeps moving.
The approach we use for our own ISO 27001 certification: evidence captured as the work happens, then assembled when it is needed.
We record where you stand against the standards that apply, so compliance is demonstrable rather than asserted.
Monitoring, change records and policy evidence are captured continuously, as part of running the technology, not bolted on before an audit.
Internal review and management oversight keep the evidence current and catch drift early.
When an audit, insurer or client asks, we assemble a pack mapped to the relevant certification or framework, ready to hand over.
The controls behind the evidence: monitoring, access control and incident response, run by a certified team. The assurance describes the security we operate.
Go to Cyber Security Start hereA one-off review of your IT, spend, security and efficiency before you commit to ongoing assurance. You own the report outright.
Explore the auditAudit and assurance is part of our governance and audit work. It builds on the documented backbone from policy frameworks and the preparation in compliance readiness. For the regulated supply chain, including defence and aerospace, this ongoing evidence is what turns a one-off certification into something a prime contractor can keep relying on.
An audit is a point-in-time review that tells you where you stand. Assurance is the ongoing work that keeps your evidence current between audits, so your compliance position stays true as systems and people change. Our standalone audit gives you that picture once, while assurance is the continuous work behind a certification you have to keep.
Typically your policies, your security configurations, your audit logs, and your certification evidence. In other words, the documents that show your controls exist, the records that show they have been operating, and the certificates that show your obligations are met. We make sure each of these exists, is current, and is mapped to the standard being assessed.
We capture monitoring and change records continuously and retain them so the trail is available when an assessor asks. The right retention period depends on the standard and the sector you operate in, so we agree it with you against your specific obligations rather than applying a single blanket figure.
We can support the technical discovery, helping you find and assemble the relevant data. The legal assessment of what to provide remains your responsibility, because that is a judgement only you can make about your own data. We handle the technical side so you can concentrate on the decision.
A platform can track tasks and store documents, which is useful. It does not operate the controls, verify that a change happened, or stand behind the security it asks you to confirm. We run and secure the technology as well as evidencing it, so the assurance describes what is in place, and one team is responsible for both.
Tell us which assessments you face and we will make sure the evidence is in order and stays that way.
Hello, I am Ainsley, the AI assistant here at Dead Simple Computing. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Replies are AI generated and can be wrong. Your messages are sent to a third-party AI service to produce them, and a member of our team can read this chat and may join it. Do not type anything confidential. See our privacy notice.