Skip to main content
Infolocklabs LLP
Governance

GRC & Compliance

Prepare for ISO 27001, SOC 2, PCI DSS, GDPR and the India DPDP Act with controls that are implemented rather than merely documented.

What it is

Governance, risk and compliance is the work of establishing which obligations apply, implementing controls that satisfy them, and producing evidence that stands up to an assessor. It is a documentation exercise only when it is done badly.

Why it matters

Certification increasingly gates commercial opportunity: enterprise procurement asks for ISO 27001 or SOC 2 before a contract, payment processing requires PCI DSS, and processing personal data brings obligations under GDPR and India's Digital Personal Data Protection Act.

The failure mode is a policy set written to pass an audit and never implemented. That survives one assessment and fails the first incident.

What Infolocklabs provides

We perform a gap assessment against the target framework, define the control set, help implement the controls that are genuinely missing, and prepare the evidence an assessor will ask for. Where a control already exists in a different form, we map it rather than duplicating it.

We are consultants, not a certification body. We prepare organisations for audit; the certificate comes from an accredited certification body appointed separately.

Frameworks and services

  • ISO/IEC 27001 readiness: scope, risk assessment, Statement of Applicability, internal audit
  • SOC 2 readiness across the applicable Trust Services Criteria
  • PCI DSS scoping and readiness
  • GDPR and India DPDP Act readiness, including data mapping and rights handling
  • IT general controls review
  • Cybersecurity audit and IT risk assessment
  • Third-party and vendor risk assessment
  • Security policy and standard development
  • Business continuity and disaster recovery planning

How we work

Controls are implemented before they are documented. Evidence collection is designed to be repeatable, because the second year of a certification is where organisations without a process struggle.

We describe compliance status accurately. We do not state that an organisation is compliant with a framework until the relevant controls are in place and evidenced.

Engagement process

How this engagement runs

Each step produces something the next one uses, so the work does not stall between phases.

  1. 01

    Scope

    Establish which frameworks apply, define the boundary and identify the systems and data in scope.

  2. 02

    Assess

    Perform a gap assessment mapping every requirement to its current implementation state.

  3. 03

    Implement

    Close the genuine gaps, then document the controls as they are actually operating.

  4. 04

    Validate

    Run an internal audit, test the evidence set and remediate what the audit surfaces.

  5. 05

    Improve

    Establish the recurring cycle of risk review, internal audit and evidence collection.

Related

  • Cybersecurity Consulting

    Assess security risk across your environment, strengthen the controls that matter and build a security strategy your team can…

  • Microsoft Intune & MDM

    Enrol, configure and control every device that touches company data, across Windows, macOS, iOS and Android, from one management…

  • Microsoft 365 Security

    Harden identity, email, collaboration and data protection across Microsoft 365 using the controls the licence you already hold…

Start with an assessment, not a proposal

Tell us what you are trying to protect and what has changed recently. We will tell you what we would look at first, and whether we are the right people for it.

Location
Gurugram, Haryana, India
GRC & Compliance Services | ISO 27001, SOC 2, DPDP | Infolocklabs LLP