Skip to content

Standards

The frameworks we work to, and what each one actually asks of you.

Buyers search by standard name, so here they are with the service that answers each. These are frameworks we work to — not accreditations the firm holds.

Standard × practiceWhich of the five practices answers each framework. Every marked cell links to that practice, and each framework name jumps to its entry below.
01Business system reviews02Information security assurance03Technology governance04Business continuity management05Project risk management
ISO/IEC 27001 Not typically engagedNot typically engagedNot typically engagedNot typically engaged
ISO 22301 Not typically engagedNot typically engagedNot typically engagedNot typically engaged
PCI DSS Not typically engagedNot typically engagedNot typically engaged
Data Protection Act, 2019 Not typically engagedNot typically engagedNot typically engagedNot typically engaged
CBK cybersecurity guidance Not typically engagedNot typically engaged
COBIT 2019 · ITIL 4 Not typically engagedNot typically engaged
SOC 2 Not typically engagedNot typically engagedNot typically engaged
  • ISO/IEC 27001

    International Organization for Standardization

    The information security management system standard. Buyers, regulators and partners increasingly ask for it by name, and certification bodies test the management system, not just the controls.

    Typical deliverable

    ISMS design, gap assessment and internal audit ahead of certification.

    Services

  • ISO 22301

    International Organization for Standardization

    The business continuity management system standard. It is what separates a continuity plan from a continuity capability: impact analysis, tested recovery, and evidence that the test happened.

    Typical deliverable

    Business impact analysis, continuity management system and exercise programme.

    Services

  • PCI DSS

    PCI Security Standards Council

    Mandatory for anyone storing, processing or transmitting card data. Scope is the whole game — most of the cost of compliance is spent on systems that never needed to be in scope.

    Typical deliverable

    Scope reduction analysis, control gap assessment and remediation plan.

    Services

  • Data Protection Act, 2019

    Republic of Kenya · Office of the Data Protection Commissioner

    Kenya’s data protection law. It obliges controllers and processors to register, to assess high-risk processing, and to be able to show their working when the ODPC asks.

    Typical deliverable

    ODPC registration support, DPIAs, processor agreements and records of processing.

    Services

  • CBK cybersecurity guidance

    Central Bank of Kenya

    Guidance for banks and payment service providers. It puts cybersecurity governance on the board’s agenda and expects reporting that survives supervisory review.

    Typical deliverable

    Self-assessment against the guidance, board reporting pack and remediation roadmap.

    Services

  • COBIT 2019 · ITIL 4

    ISACA · Axelos

    The governance and service-management frameworks our team is already certified in. Used to give decision rights and service expectations a shape the organisation can operate.

    Typical deliverable

    Governance framework design, process maturity assessment and improvement plan.

    Services

  • SOC 2

    AICPA

    The report international customers ask a service provider for before signing. Readiness work is mostly about evidence discipline — proving the control ran every time, not once.

    Typical deliverable

    Readiness assessment, control mapping and evidence-collection design.

    Services

A note on wording, because it matters in our line of work: naming a framework here means we deliver work against it — assessment, design, internal audit, readiness. It does not mean Rosewood is certified, accredited or licensed by the body that owns it. Where certification is the goal, we prepare you for the certification body; we are not one.

Gap assessment

Find out where you stand before someone else tells you.

A gap assessment against any framework on this page takes two to four weeks and produces a ranked remediation plan with effort against each item.

Request a gap assessment

+254 721 687846 taarifa@techrisk.co.ke