D-WINGS Consulting LLP
PILLAR I · ADVISORY & GRC

Governance built to certify — and to survive the second and third year.

Standards-led consulting that builds, certifies and continuously improves an organisation's governance, risk and compliance posture — from first gap assessment through to surveillance audits years later.

Talk to an ExpertSee what's included
ISO IMPLEMENTATION & CERTIFICATION
ISO/IEC 27001:2022 Implementation
End-to-end ISMS design, gap assessment, control implementation, internal audit and certification readiness support. Pre-certification VAPT is available to validate technical controls ahead of the certification audit.
ISO 22301 Implementation
Business Continuity Management System design and implementation, including BIA, continuity planning and certification readiness.
Surveillance & Recertification Support
Ongoing support for surveillance audits, management reviews and recertification cycles — the work that keeps a certificate valid after year one.
RISK & POLICY ADVISORY
Enterprise Risk Management
Risk identification, assessment, treatment planning and ongoing monitoring aligned to ISO 31000 and COBIT principles.
Policy & Framework Development
Design and maintenance of information security policies, standards and procedures aligned to ISO 27001:2022, NIST CSF and relevant regulatory frameworks.
AUDIT & ASSURANCE
ITGC Audits
IT General Controls audits covering access management, change management and operations, aligned to SOX/PCAOB expectations where applicable.
Internal Audit — IT & Security
Independent internal audit of IT and information security controls against ISO 27001, COBIT and organisational policy.
Regulatory Compliance Assessments
Compliance assessments against CERT-In directions, the DPDP Act, PCI DSS and other applicable regulatory regimes.
BUSINESS CONTINUITY & RESILIENCE
Business Continuity Planning
Business impact analysis, continuity strategy and plan development to sustain critical operations during disruption.
Disaster Recovery Advisory
DR strategy alignment with business continuity objectives and recovery time/point objectives.
SPECIALISED & EMERGING FOCUS
EV & Connected-Vehicle Cybersecurity
Advisory aligned to MoHI/MoRTH connected-vehicle cybersecurity regulatory requirements, including readiness assessments and compliance roadmaps ahead of the October 2026 deadline.
Digital Transformation Advisory
Security-by-design input into digital transformation initiatives, ensuring risk and compliance are embedded from project inception rather than retrofitted.
FRAMEWORKS & STANDARDS REFERENCED
ISO/IEC 27001ISO 22301ISO 31000COBITNIST CSFCERT-InDPDP ActPCI DSS

Engagements are aligned to these frameworks; this does not imply formal accreditation as a certification body.

Findings here don't end as a PDF.

They enter the risk register our Managed & Virtual Services pillar maintains, and are validated by the technical testing in Cybersecurity Services.

Discuss ISO 27001 readiness