Layer 06 · Assure · Project or subscription
IT Audit & Compliance Enablement
STP audits your IT ecosystem and prepares the infrastructure evidence required for ISO/IEC 27001, SOC 2, SOC 3 and HIPAA: gap assessment, remediation, evidence automation and auditor liaison. STP holds no certification of its own; we prepare and support our clients through theirs.
IT Audit & Compliance Enablement
Certification usually fails on evidence rather than on intent. The controls may genuinely be in place, but nobody can produce the access review from eight months ago, or demonstrate that backups were tested, or show that the change to the production firewall was approved.
We start with a gap assessment against the framework you are pursuing, tell you plainly what is missing, and prioritise remediation by audit risk rather than by ease. Then we make the evidence a by-product of how the infrastructure runs, instead of a quarterly scramble.
We also sit with your auditor. Translating between an auditor's control language and an engineer's configuration reality is a large part of what makes an audit cycle expensive, and it is work we are glad to absorb.
To be explicit: STP is not itself certified against these frameworks. We deliver the infrastructure, the controls and the evidence that let our clients achieve certification, and our internal practice is aligned with ISO/IEC 27001. We will never display a certification badge we have not earned.
What is included
- IT ecosystem audit and current-state documentation
- Gap assessment against ISO/IEC 27001, SOC 2, SOC 3 or HIPAA
- Prioritised remediation plan with effort and audit-risk weighting
- Technical control implementation
- Access review, logging and change management process design
- Evidence automation so artefacts are generated continuously
- Asset inventory and data flow mapping
- Policy and procedure documentation support
- Vulnerability management programme design
- Disaster recovery evidence (with the DR service)
- Auditor liaison and control walkthrough support
- Surveillance audit preparation for subsequent cycles
What you get out of it
- Evidence that exists before the auditor asks for it
- A remediation plan ordered by audit risk, not convenience
- An audit cycle that costs your team days rather than weeks
Questions
- Is STP ISO 27001 certified?
- No. STP does not hold ISO/IEC 27001 certification. We implement and audit infrastructure so that our clients can achieve and maintain it, and our internal practice (documented procedures, no single-person dependency, controlled handling of client environment data) is aligned with the standard. We state this plainly because misrepresenting certification is exactly the kind of risk our clients hire us to eliminate.
- What infrastructure evidence do ISO 27001 auditors actually ask for?
- Most commonly: an asset inventory that matches reality; access records showing joiners, movers and leavers were processed; evidence of periodic access reviews; change records for production systems; vulnerability scan results with remediation tracking; backup and restore test results; log retention proof; and documented incident handling. Almost all of it can be produced automatically if the infrastructure is instrumented for it, which is the work we do.
- How long does it take to become audit-ready?
- It depends on the starting position, which is what the gap assessment establishes. The variable is rarely the technical remediation. It is that most frameworks require a period of operating evidence, so controls must run for some months before an auditor can sample them. We will give you a realistic timeline after the assessment rather than a number before it.
IT Audit & Compliance Enablement
A live engineer calls you back within 1 hour.

