The standard was developed to mirror the best practices described within the IT Infrastructure Library (ITIL) framework and is rooted in the elements of information technology service delivery in ways to design, implement, monitor, and continually improve the delivery of information technology services.
We begin each project with your end goals in mind and to provide preparation for future key project activities. Effective communication and timely coordination of project planning activities are central to our methodology with our clients.
An ISO 20000 certification can complement other compliance efforts, such as ISO 27001, and utilizes the same management system foundation. Utilizing the same certification body for multiple ISO compliance efforts allows for audit efficiencies throughout the process and lessens the audit footprint that can be taxing for an organization and its resources.
Our experienced professionals understand the information technology service delivery landscape and can apply their knowledge to an service delivery environment to allow for an assessment that not only addresses the requirements of ISO 20000 but also the unique processes that can be identified to improve information technology service delivery.
After the agreement is executed, the first phase of the engagement is planning. This is to ensure that Schellman and the Client are fully aware of the what, who, when, why, and how prior to the beginning of testing.
Proper planning is imperative to the success of a project. Schellman has standard processes to cover the important pieces of the engagement.
The kickoff is considered the start of the engagement. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items. Schellman will be available to the client with any questions.
By including communication prior to starting, Schellman ensures that no last-minute changes to the project or team have occurred and the Client has the plan prior to the testing and on-site visit.
Testing and gathering is the core of the compliance engagement. Due to the planning and understanding processes, this phase will be an accumulation of gathering the evidence needed for the objectives discussed.
Schellman has a no surprise policy and has daily contact with the stakeholders during the testing and gathering activities. Furthermore, Schellman will begin documentation of the draft deliverable to be able to provide it to the Client efficiently after this phase. The Client will have confidence the Schellman team has completed this phase timely and completely.
Schellman’s testing methodology ends with reporting, but the entire assessment is focused on creating a deliverable that is clear, concise, and accurate.
Schellman’s report takes into account the entire process and customizes a report for each Client. The draft report will be provided within 2 weeks of the last day of testing and gathering phase, and a final report will be provided within 30 days. This timing is unsurpassed by the industry.
Ryan is a Managing Principal at Schellman. Ryan manages SOC, PCI-DSS, ISO, HIPAA and Cloud Security Alliance (CSA) STAR Certification and Attestation service delivery and also oversees the firm-wide methodology and execution for the ISO certification services, including ISO 27001, ISO 9001, ISO 20000, and ISO 22301 as well as CSA STAR certification services.
Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.
The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.
Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing: