Dip Chakraborty

Systems Engineer | Full-Stack | AI Systems

$

Establishing ISO 27001-Aligned IT Security Framework

• Security controls were fragmented, undocumented, and weakly enforced. • Built an ISO 27001-aligned framework across governance, access, endpoint hardening, and monitoring. • Converted operations into an audit-ready and risk-traceable security baseline.

Establishing ISO 27001-Aligned IT Security Framework

Executive Snapshot

RoleSecurity Architect & Lead Implementer
DurationEnterprise Compliance Transformation
Team3 Engineers
Governance:ISO 27001:2022 Annex A MappingCentralized Asset RegistryStructured Risk Register
Access & Identity:Role-Based Access ControlMFA EnforcementAccess Review Workflows
Infra Security:Full-Disk EncryptionPatch ManagementNetwork SegmentationFirewall GovernanceVPN Secure Access
Monitoring & Resilience:Centralized Log AggregationIncident Response PlaybooksBackup & Disaster Recovery (RTO/RPO)
Tools:BashPythonSelenium

Translating ISO 27001 controls into enforceable technical mechanisms across identity, infrastructure, logging, and disaster recovery without disrupting financial audit operations.

Engineering Story

Engineering Security Into Daily Operations

Transforming an audit firm's informal IT practices into an ISO 27001-aligned security framework — making controls enforceable, not theoretical.

ISO 27001SecurityGovernanceCompliance

I stepped in as IT system architect and lead implementer for the IT transformation of a respected local audit firm preparing for ISO 27001 alignment. The firm functioned day to day, but it wasn't defensible - informal policies buried in shared drives, ad-hoc admin access, no structured asset inventory, scattered risk notes in emails, weak backup validation, no centralized logging, and no incident response discipline. For a financial audit practice handling sensitive client data, that gap was dangerous.

First, I mapped their environment against ISO 27001:2022 Annex A - organizational controls (A.5), people controls (A.6), and technological controls across access, cryptography, logging, and resilience. The largest gaps were in access governance, asset and risk tracking, vendor management, backup validation, and incident handling. Instead of flooding them with templates, I focused on enforceability - controls had to live inside systems.

We established governance foundations: structured asset registers, formal risk registers with likelihood-impact scoring and treatment plans, data classification for client materials, defined access review cycles, and simple but actionable incident playbooks. On the technical side, I implemented least-privilege role-based access, enforced MFA across email and audit systems, centralized logging into a consolidated collection layer, hardened encrypted backups with tested restores and offsite retention, and introduced basic network segmentation. Vendor risk assessment templates ensured subcontractors weren't blind spots.

Every policy mapped to evidence. MFA settings, access logs, backup reports, and review artifacts weren't theoretical - they were generated by the systems themselves. Documentation reflected operational reality, not auditor theater. Staff training was tailored for non-technical auditors - practical phishing awareness and data-handling discipline without overwhelming them.

Over months, the firm transitioned from reactive IT support to a governed security posture. Risks became measurable. Access became reviewable. Incidents became reportable. Audit trails became defensible.

By delivery, the organization had a functioning ISMS backbone. Security wasn't layered on top - it was engineered into daily operations, quietly and structurally.

Features at a Glance

Problems It Solved

Business Impacts

Engineering Challenges

Continue Exploring

Enterprise Quotation & Revenue Governance Platform

View Next Case Study
Establishing ISO 27001-Aligned IT Security Framework | Financial audit firm IT security transformation | Dip Chakraborty