Skip to main content

ISO 27001 · GOLD COAST

ISO 27001 consulting for Gold Coast businesses

Know which information you hold, who can access it and where responsibility sits.

Aegentra helps Gold Coast businesses define their information security management system, implement ISO/IEC 27001:2022 and prepare evidence for independent certification. Start with the service your customers rely on, then build a manageable system around it.

Melbourne-based · Remote Gold Coast delivery · Onsite by arrangement

Discuss your scope · Check your information boundaries

03 9956 9399
Read Aegentra’s Google reviews

Business-wide feedback, including consulting and Academy training.

Modern Gold Coast high-rises lining the beach and ocean at sunrise

Build around the way information moves

  1. Customer information
  2. Applications
  3. People / suppliers
  4. Retention

A customer enquiry might enter your website, move into a CRM, reach a contractor and remain in a cloud backup after the engagement ends. Each handoff creates a question: who protects that information, and how will you demonstrate it?

The Gold Coast's economy includes health and wellbeing, tourism and events, knowledge industries and education. These are among the priority sectors identified by Invest Gold Coast. The relevant security questions depend on your services and information, rather than your postcode.

A useful ISO 27001 scope connects people, systems, locations and suppliers to the work you deliver. It also makes dependencies visible before you commit to an implementation budget.

A practical example: one service, several responsibilities

Consider a Gold Coast professional services firm using a client portal, Microsoft 365, an outsourced IT provider and specialist contractors. This is an illustrative example, not an Aegentra client case study.

The client portal provider may protect its platform. The firm still needs to decide who receives access, what contractors may download, how departures are handled and which records must be retained. Its IT provider's responsibilities also need to be agreed and evidenced.

A provider's certificate does not certify the firm's own operations. Equally, excluding a system from the proposed certification scope does not remove the risks arising from its connections.

Map those boundaries in the project scoping worksheet. Where implementation requires changes to identity, devices or cloud settings, connect the governance work with technical security improvements.

Check your customer-information boundaries

Use this checklist to identify what needs a closer look. Choose Clear, Needs work or Not sure for each statement. Leave it unanswered if you have not reviewed it.

Your selections stay on this page and clear when you leave or refresh. Do not enter customer information; this tool has no text fields.

Checklist statementNext action when “Needs work” or “Not sure” is selected
We know where customer information enters, moves and remains.Map the journey. Include forms, email, business applications, exports and backups.
We know who can access it, including contractors.Review access. Identify who approves access and how changes and departures are handled.
Our supplier responsibilities are documented.Check the handoffs. Confirm what your business, IT provider and application vendors each manage.
Our proposed scope includes the service customers need assured.Revisit the boundary. Check the service, people, systems and dependencies against the buyer's requirement.
We have evidence that these arrangements operate.Collect working evidence. Use current access reviews, supplier checks and completed operational records.
Private planning controls
We know where customer information enters, moves and remains.
We know who can access it, including contractors.
Our supplier responsibilities are documented.
Our proposed scope includes the service customers need assured.
We have evidence that these arrangements operate.

Your next actions

Choose a response to see the areas to discuss. The actions above remain available as a planning guide.

    Choose the work your business needs

    An implementation project, an internal audit and a targeted improvement programme answer different questions. Agree the scope and deliverables first, including the work retained by your team and any external provider.

    ISO 27001 implementation

    Indicative starting budget: A$12,000–15,000 + GST A$13,200–16,500 including Australian GST.

    For suitably scoped organisations with fewer than 10 people. Establish the ISMS scope, risk assessment, treatment plan, Statement of Applicability and agreed operating controls. We organise the implementation work, responsibilities and evidence, with certification-preparation support defined in your proposal. Internal audit is separately scoped unless included.

    Explore implementation deliverables

    ISO 27001 internal audit

    From A$2,300 + GST From A$2,530 including Australian GST.

    For a smaller organisation with one clear ISMS scope and straightforward evidence access. A competent auditor reviews documents, interviews control owners and samples operating evidence against the agreed criteria. Deliverables include the audit plan, documented findings and report; any corrective-action follow-up is specified in the scope.

    See the internal-audit scope

    Fast-track implementation and internal audit

    Indicative starting budget: A$15,000–18,000 + GST A$16,500–19,800 including Australian GST.

    For suitably scoped organisations with fewer than 10 people. An implementation consultant, a different internal auditor and a project manager coordinate the programme. Auditor assignment is subject to documented competence, conflict-of-interest and impartiality checks. The agreed package includes assistance arranging a certification body and preparing for Stage 1 and Stage 2.

    Discuss a coordinated programme

    What is—and is not—in the budget?

    Your starting point, services, systems, locations, existing evidence and remediation needs determine the final work. We confirm the scope and fixed fee in writing. These starting budgets are not quotes for every organisation; larger or more complex businesses need a separate scope.

    Certification-body fees are separate. Your proposal identifies any travel, licences, additional technical work and other exclusions before you commit. Compare the complete implementation and certification budget, not just the first invoice.

    Read the Australian certification cost guide

    For the complete service, see ISO 27001 implementation. If your ISMS already operates, an internal audit can examine its conformity and effectiveness.

    Delivery with clear ownership

    Aegentra is based in Melbourne and supports Gold Coast businesses remotely. Onsite work is available by arrangement, with travel quoted. Workshops should involve the people who own the services, information and technical controls being discussed.

    1. Agree the requirement and boundary

      Confirm what your customer needs, the services and information in scope, existing work, responsibilities and decision dates. Record the agreed deliverables and exclusions before implementation begins.

    2. Build and operate the ISMS

      Work through the risks, necessary controls, Statement of Applicability and operating procedures. Implement the agreed changes and collect evidence from the people and systems that perform the work.

    3. Test and review

      Arrange an objective internal audit, address findings and complete management review. The auditor must not audit their own work; appoint a separate provider if objectivity cannot be protected.

    4. Prepare for independent certification

      Organise the evidence and support agreed preparation for Stage 1 and Stage 2. The certification body controls its audit programme, findings and certification decision. Aegentra does not issue the certificate.

    Timing depends on readiness, not just headcount. For an eligible fast-track scope, 5–7 weeks is an implementation planning target, not a promised certificate date. Leadership decisions, remediation, operating evidence, audit findings and certification-body availability can change the schedule. Your written proposal records the actual plan and dependencies.

    Client feedback

    Medical clinic · ISO 27001

    We certified our medical clinic for ISO 27001 through Aegentra, and the entire process was smooth and well managed.

    Google review excerpt, reproduced with permission.

    Team and evidence

    Know who is responsible for the work

    Aegentra is based in Melbourne and delivers ISO 27001 services remotely across Australia, with onsite work by arrangement. We confirm the people assigned, their relevant qualifications, responsibilities and availability in your proposal. Travel and any onsite requirements are agreed before booking.

    Our delivery-team capability includes ISO/IEC 27001 implementation and audit qualifications, CISA, CISM and cloud-security credentials. These are held across the team—not necessarily by every consultant. The experience and credential evidence relevant to your assigned roles are confirmed before work starts.

    If Aegentra provides both implementation and internal audit, a different competent consultant who is independent of the implementation work performs the audit, subject to documented conflict and impartiality checks. If those safeguards cannot protect objectivity, a separate provider is required. Certification remains the responsibility of an independent accredited certification body.

    Meet our delivery-team capability · Read an Australian internal-audit engagement

    The linked audit case study is a published Australian engagement, not evidence of a client in this location.

    Read Aegentra's Google reviews

    Business-wide feedback, including consulting and Academy training.

    Set the certification budget against the scope

    A business with several sites and outsourced service dependencies may need a different audit programme from a single-service organisation. Compare certification-body proposals against the same scope, accreditation requirements and ongoing audit commitments.

    ANAB, IAS or JASANZ: what are you actually choosing?

    ISO/IEC 27001 is the management-system standard. An independent certification body audits your organisation and decides whether to issue a certificate. ANAB—the ANSI National Accreditation Board—IAS, the International Accreditation Service, and JASANZ are accreditation bodies: they assess certification bodies. They are not three different grades of ISO 27001.

    Check that the proposed certification body holds current accreditation for ISO/IEC 27001 and that the certificate's scope fits the services, legal entity and locations your buyer needs covered. International recognition can support acceptance, but it does not override a tender's conditions. If a customer specifies an accreditation or permits an equivalent, clarify acceptance in writing before you book.

    A certificate does not guarantee a government contract. If certification covering the work being purchased is mandatory, an unsuitable scope may leave your bid non-compliant. Meeting that requirement still does not replace the buyer's other participation conditions or evaluation criteria. Read the specific procurement documents and seek clarification where needed.

    Why can the price differ? You buy certification from a certification body, not from an accreditation logo. Audit time, complexity, sites, travel, rates, follow-up work and the ongoing audit programme affect the quote. Compare Stage 1, Stage 2, surveillance and recertification on the same scope. Do not assume ANAB is always dearer, IAS is always cheaper, or that a customer's country alone determines which certificate it will accept.

    Compare accreditation and certification costs

    Verification references: ISO: certification and accreditation, ANAB: certificate checks, ANAB: certification cost factors, IAS management-system accreditation, Commonwealth procurement evaluation. State-specific guidance is linked in the relevant city sections.

    Use the Australian certification cost guide to distinguish consulting, certification and ongoing work.

    Questions from Gold Coast businesses

    Can we certify one service rather than the whole company?

    Potentially. The scope must be defensible and address relevant boundaries, interfaces and dependencies. Check that it covers what the customer expects; an inexpensive scope that omits the purchased service may not answer their assurance request.

    Does our cloud provider's certification cover us?

    It provides information about the provider's certified scope. Your organisation still needs to manage its own decisions, responsibilities and use of the service.

    Will certification qualify us for government tenders?

    Read the specific tender. Queensland evaluates factors including capability, risk and whole-of-life value; a certificate does not replace the other requirements. Business Queensland explains the evaluation context.

    Do we need to change IT providers?

    That depends on the gaps, responsibilities and capability identified. Start by establishing what the current provider does and which evidence it can supply.

    LET'S TALK

    Start with the service you need to assure

    Tell us what your business delivers, what has prompted the project and whether there is a customer deadline. We can use that context to discuss scope and an appropriate starting point.

    Call 03 9956 9399 · Request a scope discussion

    03 9956 9399
    Overseas: +61 3 9956 9399
    Contact@aegentra.com.au

    We typically respond within 1–3 business hours.

    Your project details

    Tell us your approximate team size, the service you want covered and any customer deadline. Please do not send passwords, sensitive personal information or confidential tender documents through this form.

    We use these details to respond to your enquiry. Read our Privacy Policy.