Skip to content

Document Templates and Trainings

The ISMS Toolkit provides a comprehensive collection of document templates and training materials for the efficient implementation of an Information Security Management System (ISMS) in accordance with ISO 27001. These proven resources help organizations meet compliance requirements while saving time and resources.

Why is a structured ISMS Toolkit relevant?

Section titled “Why is a structured ISMS Toolkit relevant?”

Implementing an ISMS requires a wide range of specific documentation and policies. A standardized toolkit ensures:

  • Compliance assurance: Full coverage of ISO 27001 requirements
  • Time savings: Proven templates reduce the need to build documents from scratch
  • Quality assurance: Practical content minimizes the risk of gaps or errors
  • Scalability: Adaptable documentation for organizations of different sizes
  • Policy – Use and Management of Passwords: Secure password standards and handling
  • Policy – Access Control: Systematic monitoring of access rights
  • Policy – Authorization Management: Assignment and administration of user rights
  • Policy – Authorization Principles: Rules for granting privileges
  • Policy – Role Description and Assignment: Definition and allocation of security roles
  • Policy – Performing Risk Analyses: Systematic risk identification and evaluation
  • Policy – Control of Corrective and Preventive Actions: Structured approach to deviations
  • Policy – Control of Guidance and Evidence Documents: Documentation management for audit evidence
  • Policy – Internal Audits: Planning and execution of ISMS audits
  • Policy – Malware Protection: Prevention and handling of malware
  • Policy – Secure Remote Access: Protection of remote workplaces
  • Policy – Use of Cryptographic Measures: Encryption standards and practices
  • Policy – Network Security Documentation Overview: Security architecture for networks
  • Policy – Operation of Printers, Copiers, and MFPs: Securing peripheral devices
  • Policy – Infrastructure Security: Physical and logical infrastructure protection
  • Policy – Personnel Security: Security aspects in HR processes
  • Policy – Physical Security: Protection of facilities and premises
  • Policy – Training and Awareness: Security awareness programs for employees
  • Policy – Change Procedures: Controlled modifications to IT systems
  • Policy – Change Management: Structured implementation of changes
  • Policy – Service Rollout and Go-Live: Secure service introduction
  • Policy – Handling Security Incidents: Response to security events
  • Policy – Information Security Incident Management: Comprehensive incident process
  • Policy – Handling Malfunctions: Structured problem resolution
  • Policy – Service Level Management: Definition and monitoring of SLAs
  • Policy – Service Reports: Regular reporting on service quality
  • Policy – Business Relationship Management: Managing supplier relationships
  • Policy – Outsourcing and Contractor Management: Managing external service providers
  • Policy – Outsourcing of Security-Related Services: Requirements for critical services
  • Policy – External ISB/DSB: Integration of external security experts
  • Policy – Management of Organizational Assets: Protecting company values
  • Policy – Classification and Handling of Information: Information classification
  • Policy – IT Management: IT governance and oversight
  • Concept – ISMS Process Organization: Process-level ISMS structure
  • Concept – ISMS Organizational Structure: Structural ISMS organization
  • Template – Information Security Policy: Foundational ISMS security statement
  • Slide Deck – ISMS Tool Introduction Project: Key success factors for implementation
  • Risk Analysis – ISMS Tool Introduction: Identification and evaluation of implementation risks
  • User Handbook: Target-group-specific instructions in PDF format
  • Admin Handbook: Comprehensive administrator documentation
  • Slide Deck – User/Admin Training: Structured training materials
  • Workshop – ISMS Strategy Development: Creating an organization-specific ISMS strategy
  • Workshop – Central Policy Management for Integrated ISMS: Establishing unified policy management
  • Workshop – Emergency Planning: Basics of business continuity
  • Workshop – Building and Operating Crisis Management: Practical implementation
  • Template – Emergency Exercise Concept: Structured exercise planning
  • Workshop – Basic Risk Analysis Process: Fundamentals of risk assessment
  • Workshop – Risk Analysis: Advanced methods and techniques
  • Workshop – Structural Analysis and Protection Needs Assessment: IT-Grundschutz-compliant methodology
  • Workshop – Grundschutz Check and Profiles Methodology: Practical implementation of the BSI approach

The fuentis Suite supports practical implementation of the ISMS Toolkit with:

  • Document Management: Centralized management of ISMS documentation
  • Workflow Integration: Automated approval workflows for policies
  • Version Control: Full history of all changes
  • Audit Trail: Complete documentation of modifications for compliance evidence

Phased Implementation

  • Start with core policies (passwords, access control, incident management)
  • Expand gradually to the full documentation landscape
  • Prioritize by risk and compliance requirements

Tailoring to the Organization

  • Use templates as a starting point, not rigid rules
  • Incorporate organizational specifics
  • Involve relevant stakeholders in customization

Continuous Improvement

  • Establish regular review cycles for all documents
  • Use audit findings to improve documentation
  • Keep documentation current through change management