ISO 27001 - Quickstart Guide
ISO/IEC 27001 (ISMS) – Implementation Guide (revised)
Section titled “ISO/IEC 27001 (ISMS) – Implementation Guide (revised)”Goal: A lean, practical method to establish, certify, and continually improve an ISO/IEC 27001:2022-conformant ISMS.
Reference: Structure & terms align with your BSI/IT-Grundschutz guide (Scope, Structural Analysis, Protection Needs, Modeling, Risk Analysis) — mapped here to ISO 27001.
1) Overview & prerequisites
Section titled “1) Overview & prerequisites”When to use
- You aim for ISO/IEC 27001 certification or want to improve your ISMS in a structured way.
- You want to reuse BSI-Grundschutz artefacts (scope, structure, protection needs) as a solid baseline.
Method outcomes
- Scope, roles & governance
- Risk method, risk assessment & treatment
- Statement of Applicability (SoA) for Annex A:2022 (93 controls)
- Documented information, KPIs, audit & review cycle
2) Initiation
Section titled “2) Initiation”Objectives
- Collect relevant data (documents, interviews, workshops)
- Define the scope (ISO §4.3)
- Start the inventory of target objects/assets (structural analysis)
How to proceed
- Review existing materials (org chart, network diagram, inventories)
- Elicit missing data and store centrally (e.g., SharePoint)
- In fuentis: create target objects/assets with owner, criticality, and dependencies

Pro tip: Use the IT-Grundschutz quickstart as onboarding — terminology & artefacts transfer well to ISO.
3) ISMS framework (ISO 27001 Clauses 4–7)
Section titled “3) ISMS framework (ISO 27001 Clauses 4–7)”3.1 Context, scope & governance
Section titled “3.1 Context, scope & governance”- Context & stakeholders (ISO §4.1–4.2): determine internal/external issues, interested parties, and requirements.
- Scope (ISO §4.3): set organisational/technical boundaries (sites, processes, IT/OT).
- Governance model & roles (ISO §5.1–5.3): leadership commitment, publish ISMS policy, define roles/responsibilities (ISB/CISO, process owners).
- Maintain a RACI for key functions.

3.2 Objectives & planning (ISO §6)
Section titled “3.2 Objectives & planning (ISO §6)”- Set information security objectives (measurable, time-bound, responsible, with KPIs) aligned to business goals (ISO §6.2).
- Plan risks & opportunities (ISO §6.1): define method, criteria, acceptance (see Section 5).
3.3 Support (ISO §7)
Section titled “3.3 Support (ISO §7)”- Resources budgeted and periodically reviewed (people, time, tools, locations).
- Competence & awareness (training, on/offboarding, recurring campaigns).
- Communication (reporting flows, channels, protection).
- Documented information control (document control, versioning, retention, access).
4) Structural analysis & protection needs (ISO-compatible)
Section titled “4) Structural analysis & protection needs (ISO-compatible)”Goal: Transparent asset landscape and CIA criticality as the basis for risk assessment.
4.1 Structural analysis (ported from IT-Grundschutz)
Section titled “4.1 Structural analysis (ported from IT-Grundschutz)”- Capture business processes, applications, IT/OT systems, buildings/rooms, service providers.
- Create TOG/asset groups (servers, clients, network, apps, sites) for clarity & maintainability.
- Record process/system dependencies (fuentis relations).

4.2 Determining protection needs (CIA)
Section titled “4.2 Determining protection needs (CIA)”- Rate Confidentiality / Integrity / Availability per asset/process: normal / high / very high.
- Use inheritance (e.g., process → application → system; watch aggregation effects).

5) Risk management (ISO §6.1 & §8)
Section titled “5) Risk management (ISO §6.1 & §8)”5.1 Method & criteria
Section titled “5.1 Method & criteria”- Approach: scenario-based risk identification (threat × vulnerability × impact).
- Define criteria: likelihood, impact (CIA), scoring model, acceptance thresholds, treatment rules, combined risks.

5.2 Risk assessment
Section titled “5.2 Risk assessment”- Identify → analyse → evaluate risks (consistent, repeatable).
- Assign risk owners, determine residual risk & priority, maintain the register.
5.3 Risk treatment
Section titled “5.3 Risk treatment”- Choose option (avoid, mitigate, share/transfer, accept) and derive controls from Annex A.
- Build/maintain the Statement of Applicability (SoA): applicable/not applicable + justification, status, references.
- Create a treatment plan with owners, due dates, and evidence (tests, artefacts).
Pro tip (fuentis): Link risks to target objects & measures; use the “Risk Treatment” workflow for automated tasks.
6) Implementation (DO)
Section titled “6) Implementation (DO)”6.1 Implement controls
Section titled “6.1 Implement controls”- Plan resources & costs (one-off/recurring), sequence by risk & quick wins.
- Deploy technical/organisational controls, test effectiveness, collect evidence.
- Reassess and document residual risk.
6.2 Keep the SoA current
Section titled “6.2 Keep the SoA current”- Update after every major change/reassessment with status & justifications.
- Obtain management confirmation.
6.3 Training & awareness
Section titled “6.3 Training & awareness”- Deliver role-specific training; run campaigns cyclically.
- Measure impact via KPIs (e.g., phishing rate, completion scores).
7) Monitoring & review (CHECK – ISO §9)
Section titled “7) Monitoring & review (CHECK – ISO §9)”7.1 Monitoring & KPIs
Section titled “7.1 Monitoring & KPIs”- What is monitored (controls, processes, incidents)?
- How (method), how often (frequency), by whom (role)?
- Define KPIs (e.g., patch SLA, incident MTTR, backup success rate) and report.
7.2 Internal audit
Section titled “7.2 Internal audit”- Set programme & criteria, ensure independence.
- Record findings, nonconformities, and improvement opportunities.
7.3 Management review
Section titled “7.3 Management review”- Inputs: KPI reports, audit results, incidents, status of objectives/SoA/risks.
- Outputs: decisions, resources, priorities, improvement directives.
8) Improvement (ACT – ISO §10)
Section titled “8) Improvement (ACT – ISO §10)”- Manage nonconformities & corrective actions (root cause, effectiveness check).
- Continual ISMS improvement (objectives, processes, controls, documentation).
9) Artefacts (minimal set)
Section titled “9) Artefacts (minimal set)”| Artefact | Purpose |
|---|---|
| ISMS policy | Guardrails & leadership commitment |
| Context, stakeholders, scope | ISO §4 evidence, boundaries |
| Organisation structure & RACI | Transparent roles/responsibilities |
| Asset/structure map | Basis for protection needs & risks |
| Protection needs (CIA) | Criticality & inheritance documented |
| Risk method & criteria | Uniform, repeatable assessment |
| Risk register | Identification, evaluation, owner, status |
| SoA (Annex A:2022) | Applicability, justification, status |
| Action plan & evidence | Implementation & effectiveness traceable |
| KPI set, audit plan, management review | Oversight & steering |
10) ISO 27001 vs. BSI IT-Grundschutz (at a glance)
Section titled “10) ISO 27001 vs. BSI IT-Grundschutz (at a glance)”- ISO 27001: Process-oriented, risk-based; certifies the management system, not a fixed security level.
- Grundschutz: Measures catalogue & implementation aids; risk analysis sometimes dispensable; certification reflects a security level.
- In practice: Grundschutz artefacts (structure, protection needs) accelerate ISO rollout; ISO always requires formal risk assessment and an SoA.
11) Annex – examples & snippets
Section titled “11) Annex – examples & snippets”11.1 CIA categories
Section titled “11.1 CIA categories”| Category | Definition |
|---|---|
| normal | Limited, manageable impact |
| high | Considerable impact |
| very high | Existential/catastrophic impact |
11.2 Risk prompt (guiding questions)
Section titled “11.2 Risk prompt (guiding questions)”- What is the acceptable residual risk per asset/process?
- Which treatment strategy applies per risk band (red/amber/green)?
- How do we measure effectiveness (KPIs, tests, evidence)?
12) Quick checks (for audits & go-lives)
Section titled “12) Quick checks (for audits & go-lives)”- Scope complete; boundaries & interfaces clear
- Roles/RACI published; responsibilities enacted
- Method & criteria written; consistently applied
- Risk register current; owners & due dates set
- SoA current; justifications traceable
- Controls effective (tests/evidence available)
- KPI reporting, internal audit & management review done
- Corrective actions tracked; effectiveness verified