Audit and compliance
ISMS
Also called: information security management system
An information security management system is the documented set of policies, processes and controls, and the governance around them, that an organization uses to manage information security risk. ISO 27001 certifies the management system, not any individual control.
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.