Establishing ISO 27001-Aligned IT Security Framework
• Security controls were fragmented, undocumented, and weakly enforced. • Built an ISO 27001-aligned framework across governance, access, endpoint hardening, and monitoring. • Converted operations into an audit-ready and risk-traceable security baseline.

Executive Snapshot
Translating ISO 27001 controls into enforceable technical mechanisms across identity, infrastructure, logging, and disaster recovery without disrupting financial audit operations.
Engineering Security Into Daily Operations
Transforming an audit firm's informal IT practices into an ISO 27001-aligned security framework — making controls enforceable, not theoretical.
I stepped in as IT system architect and lead implementer for the IT transformation of a respected local audit firm preparing for ISO 27001 alignment. The firm functioned day to day, but it wasn't defensible - informal policies buried in shared drives, ad-hoc admin access, no structured asset inventory, scattered risk notes in emails, weak backup validation, no centralized logging, and no incident response discipline. For a financial audit practice handling sensitive client data, that gap was dangerous.
First, I mapped their environment against ISO 27001:2022 Annex A - organizational controls (A.5), people controls (A.6), and technological controls across access, cryptography, logging, and resilience. The largest gaps were in access governance, asset and risk tracking, vendor management, backup validation, and incident handling. Instead of flooding them with templates, I focused on enforceability - controls had to live inside systems.
We established governance foundations: structured asset registers, formal risk registers with likelihood-impact scoring and treatment plans, data classification for client materials, defined access review cycles, and simple but actionable incident playbooks. On the technical side, I implemented least-privilege role-based access, enforced MFA across email and audit systems, centralized logging into a consolidated collection layer, hardened encrypted backups with tested restores and offsite retention, and introduced basic network segmentation. Vendor risk assessment templates ensured subcontractors weren't blind spots.
Every policy mapped to evidence. MFA settings, access logs, backup reports, and review artifacts weren't theoretical - they were generated by the systems themselves. Documentation reflected operational reality, not auditor theater. Staff training was tailored for non-technical auditors - practical phishing awareness and data-handling discipline without overwhelming them.
Over months, the firm transitioned from reactive IT support to a governed security posture. Risks became measurable. Access became reviewable. Incidents became reportable. Audit trails became defensible.
By delivery, the organization had a functioning ISMS backbone. Security wasn't layered on top - it was engineered into daily operations, quietly and structurally.