Aim: help you detect if you already have sufficient basis to start an ISMS and what gaps should be resolved first.
1. Scope and context
- It is clear which services, locations, equipment and processes fall into the ISMS.
- Interested parties have been identified: clients, suppliers, employees, administration, partners and the certifier.
- There are documented contractual, legal or regulatory requirements.
2. Assets and critical information
- There is inventory of assets: data, applications, infrastructure, devices and providers.
- It is known what information is confidential, sensitive or critical to operate.
- Asset owners and process managers are identified.
3. Risks and treatment
- Threats, vulnerabilities, impact and probability are evaluated.
- Management accepts, reduces, transfers or avoids risks with clear criteria.
- There is a treatment plan with those responsible and dates.
4. Controls and SoA
- It is justified which Annex A controls apply and which do not.
- Access control, copies, continuity, suppliers, incidents and training are covered.
- The decisions remain in a maintainable Statement of Applicability.
5. Evidence and audit
- There are training records, reviews, incidents, corrective actions and internal audit.
- Documentation reflects how the company really works.
- There is a management review and a continuous improvement plan.
Frequent errors
- Buy templates and not implement them.
- Define too large a scope for the first certification.
- Do not assign internal managers.
- Confuse “having policies” with having evidence.
- Do not connect ISO 27001 with ENS, NIS2, GDPR or customer requirements.
Do you want to know where to start?
Blue Moon Cybertech can make an initial diagnosis and turn this checklist into a roadmap with priorities, times and deliverables.