Skip to content

ISO 27001 - Quickstart Guide

ISO/IEC 27001 (ISMS) – Implementation Guide (revised)

Section titled “ISO/IEC 27001 (ISMS) – Implementation Guide (revised)”

Goal: A lean, practical method to establish, certify, and continually improve an ISO/IEC 27001:2022-conformant ISMS.
Reference: Structure & terms align with your BSI/IT-Grundschutz guide (Scope, Structural Analysis, Protection Needs, Modeling, Risk Analysis) — mapped here to ISO 27001.


When to use

  • You aim for ISO/IEC 27001 certification or want to improve your ISMS in a structured way.
  • You want to reuse BSI-Grundschutz artefacts (scope, structure, protection needs) as a solid baseline.

Method outcomes

  • Scope, roles & governance
  • Risk method, risk assessment & treatment
  • Statement of Applicability (SoA) for Annex A:2022 (93 controls)
  • Documented information, KPIs, audit & review cycle

Objectives

  • Collect relevant data (documents, interviews, workshops)
  • Define the scope (ISO §4.3)
  • Start the inventory of target objects/assets (structural analysis)

How to proceed

  • Review existing materials (org chart, network diagram, inventories)
  • Elicit missing data and store centrally (e.g., SharePoint)
  • In fuentis: create target objects/assets with owner, criticality, and dependencies

Initiation

Pro tip: Use the IT-Grundschutz quickstart as onboarding — terminology & artefacts transfer well to ISO.


3) ISMS framework (ISO 27001 Clauses 4–7)

Section titled “3) ISMS framework (ISO 27001 Clauses 4–7)”
  • Context & stakeholders (ISO §4.1–4.2): determine internal/external issues, interested parties, and requirements.
  • Scope (ISO §4.3): set organisational/technical boundaries (sites, processes, IT/OT).
  • Governance model & roles (ISO §5.1–5.3): leadership commitment, publish ISMS policy, define roles/responsibilities (ISB/CISO, process owners).
  • Maintain a RACI for key functions.

Information security organisation

  • Set information security objectives (measurable, time-bound, responsible, with KPIs) aligned to business goals (ISO §6.2).
  • Plan risks & opportunities (ISO §6.1): define method, criteria, acceptance (see Section 5).
  • Resources budgeted and periodically reviewed (people, time, tools, locations).
  • Competence & awareness (training, on/offboarding, recurring campaigns).
  • Communication (reporting flows, channels, protection).
  • Documented information control (document control, versioning, retention, access).

4) Structural analysis & protection needs (ISO-compatible)

Section titled “4) Structural analysis & protection needs (ISO-compatible)”

Goal: Transparent asset landscape and CIA criticality as the basis for risk assessment.

4.1 Structural analysis (ported from IT-Grundschutz)

Section titled “4.1 Structural analysis (ported from IT-Grundschutz)”
  • Capture business processes, applications, IT/OT systems, buildings/rooms, service providers.
  • Create TOG/asset groups (servers, clients, network, apps, sites) for clarity & maintainability.
  • Record process/system dependencies (fuentis relations).

TOG

  • Rate Confidentiality / Integrity / Availability per asset/process: normal / high / very high.
  • Use inheritance (e.g., process → application → system; watch aggregation effects).

Protection needs


  • Approach: scenario-based risk identification (threat × vulnerability × impact).
  • Define criteria: likelihood, impact (CIA), scoring model, acceptance thresholds, treatment rules, combined risks.

Risk

  • Identify → analyse → evaluate risks (consistent, repeatable).
  • Assign risk owners, determine residual risk & priority, maintain the register.
  • Choose option (avoid, mitigate, share/transfer, accept) and derive controls from Annex A.
  • Build/maintain the Statement of Applicability (SoA): applicable/not applicable + justification, status, references.
  • Create a treatment plan with owners, due dates, and evidence (tests, artefacts).

Pro tip (fuentis): Link risks to target objects & measures; use the “Risk Treatment” workflow for automated tasks.


  • Plan resources & costs (one-off/recurring), sequence by risk & quick wins.
  • Deploy technical/organisational controls, test effectiveness, collect evidence.
  • Reassess and document residual risk.
  • Update after every major change/reassessment with status & justifications.
  • Obtain management confirmation.
  • Deliver role-specific training; run campaigns cyclically.
  • Measure impact via KPIs (e.g., phishing rate, completion scores).

7) Monitoring & review (CHECK – ISO §9)

Section titled “7) Monitoring & review (CHECK – ISO §9)”
  • What is monitored (controls, processes, incidents)?
  • How (method), how often (frequency), by whom (role)?
  • Define KPIs (e.g., patch SLA, incident MTTR, backup success rate) and report.
  • Set programme & criteria, ensure independence.
  • Record findings, nonconformities, and improvement opportunities.
  • Inputs: KPI reports, audit results, incidents, status of objectives/SoA/risks.
  • Outputs: decisions, resources, priorities, improvement directives.

  • Manage nonconformities & corrective actions (root cause, effectiveness check).
  • Continual ISMS improvement (objectives, processes, controls, documentation).

ArtefactPurpose
ISMS policyGuardrails & leadership commitment
Context, stakeholders, scopeISO §4 evidence, boundaries
Organisation structure & RACITransparent roles/responsibilities
Asset/structure mapBasis for protection needs & risks
Protection needs (CIA)Criticality & inheritance documented
Risk method & criteriaUniform, repeatable assessment
Risk registerIdentification, evaluation, owner, status
SoA (Annex A:2022)Applicability, justification, status
Action plan & evidenceImplementation & effectiveness traceable
KPI set, audit plan, management reviewOversight & steering

10) ISO 27001 vs. BSI IT-Grundschutz (at a glance)

Section titled “10) ISO 27001 vs. BSI IT-Grundschutz (at a glance)”
  • ISO 27001: Process-oriented, risk-based; certifies the management system, not a fixed security level.
  • Grundschutz: Measures catalogue & implementation aids; risk analysis sometimes dispensable; certification reflects a security level.
  • In practice: Grundschutz artefacts (structure, protection needs) accelerate ISO rollout; ISO always requires formal risk assessment and an SoA.

CategoryDefinition
normalLimited, manageable impact
highConsiderable impact
very highExistential/catastrophic impact
  • What is the acceptable residual risk per asset/process?
  • Which treatment strategy applies per risk band (red/amber/green)?
  • How do we measure effectiveness (KPIs, tests, evidence)?

  • Scope complete; boundaries & interfaces clear
  • Roles/RACI published; responsibilities enacted
  • Method & criteria written; consistently applied
  • Risk register current; owners & due dates set
  • SoA current; justifications traceable
  • Controls effective (tests/evidence available)
  • KPI reporting, internal audit & management review done
  • Corrective actions tracked; effectiveness verified