GRC & Compliance
Prepare for ISO 27001, SOC 2, PCI DSS, GDPR and the India DPDP Act with controls that are implemented rather than merely documented.
What it is
Governance, risk and compliance is the work of establishing which obligations apply, implementing controls that satisfy them, and producing evidence that stands up to an assessor. It is a documentation exercise only when it is done badly.
Why it matters
Certification increasingly gates commercial opportunity: enterprise procurement asks for ISO 27001 or SOC 2 before a contract, payment processing requires PCI DSS, and processing personal data brings obligations under GDPR and India's Digital Personal Data Protection Act.
The failure mode is a policy set written to pass an audit and never implemented. That survives one assessment and fails the first incident.
What Infolocklabs provides
We perform a gap assessment against the target framework, define the control set, help implement the controls that are genuinely missing, and prepare the evidence an assessor will ask for. Where a control already exists in a different form, we map it rather than duplicating it.
We are consultants, not a certification body. We prepare organisations for audit; the certificate comes from an accredited certification body appointed separately.
Frameworks and services
- ISO/IEC 27001 readiness: scope, risk assessment, Statement of Applicability, internal audit
- SOC 2 readiness across the applicable Trust Services Criteria
- PCI DSS scoping and readiness
- GDPR and India DPDP Act readiness, including data mapping and rights handling
- IT general controls review
- Cybersecurity audit and IT risk assessment
- Third-party and vendor risk assessment
- Security policy and standard development
- Business continuity and disaster recovery planning
How we work
Controls are implemented before they are documented. Evidence collection is designed to be repeatable, because the second year of a certification is where organisations without a process struggle.
We describe compliance status accurately. We do not state that an organisation is compliant with a framework until the relevant controls are in place and evidenced.
Engagement process
How this engagement runs
Each step produces something the next one uses, so the work does not stall between phases.
- 01
Scope
Establish which frameworks apply, define the boundary and identify the systems and data in scope.
- 02
Assess
Perform a gap assessment mapping every requirement to its current implementation state.
- 03
Implement
Close the genuine gaps, then document the controls as they are actually operating.
- 04
Validate
Run an internal audit, test the evidence set and remediate what the audit surfaces.
- 05
Improve
Establish the recurring cycle of risk review, internal audit and evidence collection.
Related
Often scoped alongside this
Cybersecurity Consulting
Assess security risk across your environment, strengthen the controls that matter and build a security strategy your team can…
Microsoft Intune & MDM
Enrol, configure and control every device that touches company data, across Windows, macOS, iOS and Android, from one management…
Microsoft 365 Security
Harden identity, email, collaboration and data protection across Microsoft 365 using the controls the licence you already hold…
Start with an assessment, not a proposal
Tell us what you are trying to protect and what has changed recently. We will tell you what we would look at first, and whether we are the right people for it.
- Phone
- +91 9372406405
- Location
- Gurugram, Haryana, India