Document Templates and Trainings
The ISMS Toolkit provides a comprehensive collection of document templates and training materials for the efficient implementation of an Information Security Management System (ISMS) in accordance with ISO 27001. These proven resources help organizations meet compliance requirements while saving time and resources.
Why is a structured ISMS Toolkit relevant?
Section titled “Why is a structured ISMS Toolkit relevant?”Implementing an ISMS requires a wide range of specific documentation and policies. A standardized toolkit ensures:
- Compliance assurance: Full coverage of ISO 27001 requirements
- Time savings: Proven templates reduce the need to build documents from scratch
- Quality assurance: Practical content minimizes the risk of gaps or errors
- Scalability: Adaptable documentation for organizations of different sizes
ISMS Document Templates
Section titled “ISMS Document Templates”Core Information Security Policies
Section titled “Core Information Security Policies”Access and Authorization Management
Section titled “Access and Authorization Management”- Policy – Use and Management of Passwords: Secure password standards and handling
- Policy – Access Control: Systematic monitoring of access rights
- Policy – Authorization Management: Assignment and administration of user rights
- Policy – Authorization Principles: Rules for granting privileges
- Policy – Role Description and Assignment: Definition and allocation of security roles
Risk Management and Compliance
Section titled “Risk Management and Compliance”- Policy – Performing Risk Analyses: Systematic risk identification and evaluation
- Policy – Control of Corrective and Preventive Actions: Structured approach to deviations
- Policy – Control of Guidance and Evidence Documents: Documentation management for audit evidence
- Policy – Internal Audits: Planning and execution of ISMS audits
Technical Security Measures
Section titled “Technical Security Measures”- Policy – Malware Protection: Prevention and handling of malware
- Policy – Secure Remote Access: Protection of remote workplaces
- Policy – Use of Cryptographic Measures: Encryption standards and practices
- Policy – Network Security Documentation Overview: Security architecture for networks
- Policy – Operation of Printers, Copiers, and MFPs: Securing peripheral devices
Organizational Security
Section titled “Organizational Security”- Policy – Infrastructure Security: Physical and logical infrastructure protection
- Policy – Personnel Security: Security aspects in HR processes
- Policy – Physical Security: Protection of facilities and premises
- Policy – Training and Awareness: Security awareness programs for employees
Process and Service Management
Section titled “Process and Service Management”Change and Configuration Management
Section titled “Change and Configuration Management”- Policy – Change Procedures: Controlled modifications to IT systems
- Policy – Change Management: Structured implementation of changes
- Policy – Service Rollout and Go-Live: Secure service introduction
Incident and Problem Management
Section titled “Incident and Problem Management”- Policy – Handling Security Incidents: Response to security events
- Policy – Information Security Incident Management: Comprehensive incident process
- Policy – Handling Malfunctions: Structured problem resolution
Service Quality and Control
Section titled “Service Quality and Control”- Policy – Service Level Management: Definition and monitoring of SLAs
- Policy – Service Reports: Regular reporting on service quality
- Policy – Business Relationship Management: Managing supplier relationships
Strategic and Governance Aspects
Section titled “Strategic and Governance Aspects”Outsourcing and Third Parties
Section titled “Outsourcing and Third Parties”- Policy – Outsourcing and Contractor Management: Managing external service providers
- Policy – Outsourcing of Security-Related Services: Requirements for critical services
- Policy – External ISB/DSB: Integration of external security experts
Asset and Value Management
Section titled “Asset and Value Management”- Policy – Management of Organizational Assets: Protecting company values
- Policy – Classification and Handling of Information: Information classification
- Policy – IT Management: IT governance and oversight
Organizational Concepts
Section titled “Organizational Concepts”- Concept – ISMS Process Organization: Process-level ISMS structure
- Concept – ISMS Organizational Structure: Structural ISMS organization
- Template – Information Security Policy: Foundational ISMS security statement
ISMS Tool Trainings & Workshops
Section titled “ISMS Tool Trainings & Workshops”Introduction and Basics
Section titled “Introduction and Basics”Project Initiation
Section titled “Project Initiation”- Slide Deck – ISMS Tool Introduction Project: Key success factors for implementation
- Risk Analysis – ISMS Tool Introduction: Identification and evaluation of implementation risks
User and Admin Documentation
Section titled “User and Admin Documentation”- User Handbook: Target-group-specific instructions in PDF format
- Admin Handbook: Comprehensive administrator documentation
- Slide Deck – User/Admin Training: Structured training materials
Specialized Workshops
Section titled “Specialized Workshops”Strategy Development
Section titled “Strategy Development”- Workshop – ISMS Strategy Development: Creating an organization-specific ISMS strategy
- Workshop – Central Policy Management for Integrated ISMS: Establishing unified policy management
Emergency and Crisis Management
Section titled “Emergency and Crisis Management”- Workshop – Emergency Planning: Basics of business continuity
- Workshop – Building and Operating Crisis Management: Practical implementation
- Template – Emergency Exercise Concept: Structured exercise planning
Risk Management
Section titled “Risk Management”- Workshop – Basic Risk Analysis Process: Fundamentals of risk assessment
- Workshop – Risk Analysis: Advanced methods and techniques
- Workshop – Structural Analysis and Protection Needs Assessment: IT-Grundschutz-compliant methodology
BSI IT-Grundschutz
Section titled “BSI IT-Grundschutz”- Workshop – Grundschutz Check and Profiles Methodology: Practical implementation of the BSI approach
Implementation Aids and Best Practices
Section titled “Implementation Aids and Best Practices”Integration into the fuentis Suite
Section titled “Integration into the fuentis Suite”The fuentis Suite supports practical implementation of the ISMS Toolkit with:
- Document Management: Centralized management of ISMS documentation
- Workflow Integration: Automated approval workflows for policies
- Version Control: Full history of all changes
- Audit Trail: Complete documentation of modifications for compliance evidence
Practical Tips for Implementation
Section titled “Practical Tips for Implementation”Phased Implementation
- Start with core policies (passwords, access control, incident management)
- Expand gradually to the full documentation landscape
- Prioritize by risk and compliance requirements
Tailoring to the Organization
- Use templates as a starting point, not rigid rules
- Incorporate organizational specifics
- Involve relevant stakeholders in customization
Continuous Improvement
- Establish regular review cycles for all documents
- Use audit findings to improve documentation
- Keep documentation current through change management