← Security and Trust Centre
Framework 3 of 4

ISO/IEC 27001:2022

A formal Information Security Management System (ISMS) that continuously identifies, manages, monitors and improves information security risk — not a one-off checklist.

ISMS BUILD IN PROGRESSTarget: 90–120 days to certification readiness, then formal audit
Why ISO 27001 matters for FM clients

RaptorFM's clients trust us with customer, employee, building, maintenance, contractor, financial and operational data across every site they manage. ISO 27001 isn't a checklist — it's a formal, independently certified Information Security Management System that continuously identifies, manages, monitors and improves the risk around that data, which is exactly the level of assurance facilities management procurement teams expect from a system of record.

ISMS build areas

This is early-stage — most areas are in progress or planned, and that's stated honestly below.

Governance
IN PROGRESS
  • Information Security Policy
  • Security roles & responsibilities
  • Management commitment
  • Security objectives
Risk Management
IN PROGRESS
  • Risk methodology
  • Asset inventory
  • Risk register
  • Risk treatment plan
  • Statement of Applicability
Technical Security
IN PROGRESS
  • Access control
  • Multi-factor authentication
  • Encryption
  • Logging & monitoring
  • Vulnerability management
  • Secure development
  • Backups
  • Disaster recovery
  • Endpoint & network security
People
PLANNED
  • Onboarding / offboarding
  • Security awareness training
  • Confidentiality agreements
  • Acceptable use policy
Suppliers
PLANNED
  • Vendor risk assessment
  • Supplier security requirements
  • Subprocessor management
Incident Management
PLANNED
  • Incident response
  • Breach management
  • Escalation paths
  • Lessons-learned process
Business Continuity
PLANNED
  • Business Continuity Plan
  • Disaster recovery
  • Backup testing
  • Recovery time / point objectives
Continuous Improvement
PLANNED
  • Internal audits
  • Management reviews
  • Corrective actions
Readiness timeline
Month 1

Governance framework and risk register established; asset inventory built.

Month 2

Technical controls implemented across access, encryption, logging and backups.

Month 3

Internal audit run against ISO/IEC 27001:2022; gaps remediated.

Month 4

Formal certification audit with an accredited certification body.

Request the ISO 27001 roadmap & status

Get our current Statement of Applicability status, risk register summary and certification roadmap under NDA.

Request the pack →