RaptorFM's clients trust us with customer, employee, building, maintenance, contractor, financial and operational data across every site they manage. ISO 27001 isn't a checklist — it's a formal, independently certified Information Security Management System that continuously identifies, manages, monitors and improves the risk around that data, which is exactly the level of assurance facilities management procurement teams expect from a system of record.
This is early-stage — most areas are in progress or planned, and that's stated honestly below.
- Information Security Policy
- Security roles & responsibilities
- Management commitment
- Security objectives
- Risk methodology
- Asset inventory
- Risk register
- Risk treatment plan
- Statement of Applicability
- Access control
- Multi-factor authentication
- Encryption
- Logging & monitoring
- Vulnerability management
- Secure development
- Backups
- Disaster recovery
- Endpoint & network security
- Onboarding / offboarding
- Security awareness training
- Confidentiality agreements
- Acceptable use policy
- Vendor risk assessment
- Supplier security requirements
- Subprocessor management
- Incident response
- Breach management
- Escalation paths
- Lessons-learned process
- Business Continuity Plan
- Disaster recovery
- Backup testing
- Recovery time / point objectives
- Internal audits
- Management reviews
- Corrective actions
Governance framework and risk register established; asset inventory built.
Technical controls implemented across access, encryption, logging and backups.
Internal audit run against ISO/IEC 27001:2022; gaps remediated.
Formal certification audit with an accredited certification body.
Get our current Statement of Applicability status, risk register summary and certification roadmap under NDA.