Standards
The frameworks we work to, and what each one actually asks of you.
Buyers search by standard name, so here they are with the service that answers each. These are frameworks we work to — not accreditations the firm holds.
| 01Business system reviews | 02Information security assurance | 03Technology governance | 04Business continuity management | 05Project risk management | |
|---|---|---|---|---|---|
| ISO/IEC 27001 | Not typically engaged | Not typically engaged | Not typically engaged | Not typically engaged | |
| ISO 22301 | Not typically engaged | Not typically engaged | Not typically engaged | Not typically engaged | |
| PCI DSS | Not typically engaged | Not typically engaged | Not typically engaged | ||
| Data Protection Act, 2019 | Not typically engaged | Not typically engaged | Not typically engaged | Not typically engaged | |
| CBK cybersecurity guidance | Not typically engaged | Not typically engaged | |||
| COBIT 2019 · ITIL 4 | Not typically engaged | Not typically engaged | |||
| SOC 2 | Not typically engaged | Not typically engaged | Not typically engaged |
| Framework | What it asks of you | Services | Typical deliverable |
|---|---|---|---|
| ISO/IEC 27001International Organization for Standardization | The information security management system standard. Buyers, regulators and partners increasingly ask for it by name, and certification bodies test the management system, not just the controls. | ISMS design, gap assessment and internal audit ahead of certification. | |
| ISO 22301International Organization for Standardization | The business continuity management system standard. It is what separates a continuity plan from a continuity capability: impact analysis, tested recovery, and evidence that the test happened. | Business impact analysis, continuity management system and exercise programme. | |
| PCI DSSPCI Security Standards Council | Mandatory for anyone storing, processing or transmitting card data. Scope is the whole game — most of the cost of compliance is spent on systems that never needed to be in scope. | Scope reduction analysis, control gap assessment and remediation plan. | |
| Data Protection Act, 2019Republic of Kenya · Office of the Data Protection Commissioner | Kenya’s data protection law. It obliges controllers and processors to register, to assess high-risk processing, and to be able to show their working when the ODPC asks. | ODPC registration support, DPIAs, processor agreements and records of processing. | |
| CBK cybersecurity guidanceCentral Bank of Kenya | Guidance for banks and payment service providers. It puts cybersecurity governance on the board’s agenda and expects reporting that survives supervisory review. | Self-assessment against the guidance, board reporting pack and remediation roadmap. | |
| COBIT 2019 · ITIL 4ISACA · Axelos | The governance and service-management frameworks our team is already certified in. Used to give decision rights and service expectations a shape the organisation can operate. | Governance framework design, process maturity assessment and improvement plan. | |
| SOC 2AICPA | The report international customers ask a service provider for before signing. Readiness work is mostly about evidence discipline — proving the control ran every time, not once. | Readiness assessment, control mapping and evidence-collection design. |
ISO/IEC 27001
International Organization for Standardization
The information security management system standard. Buyers, regulators and partners increasingly ask for it by name, and certification bodies test the management system, not just the controls.
Typical deliverable
ISMS design, gap assessment and internal audit ahead of certification.
Services
ISO 22301
International Organization for Standardization
The business continuity management system standard. It is what separates a continuity plan from a continuity capability: impact analysis, tested recovery, and evidence that the test happened.
Typical deliverable
Business impact analysis, continuity management system and exercise programme.
Services
PCI DSS
PCI Security Standards Council
Mandatory for anyone storing, processing or transmitting card data. Scope is the whole game — most of the cost of compliance is spent on systems that never needed to be in scope.
Typical deliverable
Scope reduction analysis, control gap assessment and remediation plan.
Services
Data Protection Act, 2019
Republic of Kenya · Office of the Data Protection Commissioner
Kenya’s data protection law. It obliges controllers and processors to register, to assess high-risk processing, and to be able to show their working when the ODPC asks.
Typical deliverable
ODPC registration support, DPIAs, processor agreements and records of processing.
Services
CBK cybersecurity guidance
Central Bank of Kenya
Guidance for banks and payment service providers. It puts cybersecurity governance on the board’s agenda and expects reporting that survives supervisory review.
Typical deliverable
Self-assessment against the guidance, board reporting pack and remediation roadmap.
Services
COBIT 2019 · ITIL 4
ISACA · Axelos
The governance and service-management frameworks our team is already certified in. Used to give decision rights and service expectations a shape the organisation can operate.
Typical deliverable
Governance framework design, process maturity assessment and improvement plan.
Services
SOC 2
AICPA
The report international customers ask a service provider for before signing. Readiness work is mostly about evidence discipline — proving the control ran every time, not once.
Typical deliverable
Readiness assessment, control mapping and evidence-collection design.
Services
A note on wording, because it matters in our line of work: naming a framework here means we deliver work against it — assessment, design, internal audit, readiness. It does not mean Rosewood is certified, accredited or licensed by the body that owns it. Where certification is the goal, we prepare you for the certification body; we are not one.
Gap assessment
Find out where you stand before someone else tells you.
A gap assessment against any framework on this page takes two to four weeks and produces a ranked remediation plan with effort against each item.
+254 721 687846 taarifa@techrisk.co.ke