Readiness is an operating model exercise, not a documentation sprint
The objective is to establish a proportionate Information Security Management System that protects the services, information and dependencies that matter most, and that can be demonstrated through consistent evidence.
PFGsec point of view
Build a minimum viable ISMS around critical services and real business risk. A smaller, defensible scope is stronger than an ambitious scope the organization cannot operate consistently.
01 Scope is a business decision
Define services, locations, information, technology, people and suppliers, not merely an IT boundary.
02 Risk drives controls
Select controls because of assessed risk and obligations, not because they appear in a generic template.
03 Evidence beats volume
A few well operated processes with reliable records are stronger than an unused policy library.
04 Management owns the ISMS
Leadership sets direction, assigns resources, accepts residual risk and reviews performance.
05 Certification is a checkpoint
The system continues through monitoring, audit, corrective action and improvement.
06 Traceability creates confidence
Scope, risk, controls, evidence and assurance should tell one connected management story.
What good looks like
- Leadership reviews objectives, risk owners make treatment decisions, control owners retain evidence and management closes nonconformities through normal governance.
Failure pattern
- The programme becomes a document collection exercise while operational teams continue working without defined evidence or accountability.
Executive test
- Can management explain what is in scope, which risks matter, who owns treatment and what evidence demonstrates operation?
Decisions to make before mobilization
| Leadership decision | Expected outcome |
|---|---|
| Business outcome | Define the commercial, regulatory or operational outcome the programme should support. |
| Certification boundary | Approve the services, locations, information, systems, suppliers and interfaces in scope. |
| Decision authority | Name who can approve scope, accept residual risk and close material corrective actions. |
| Operating commitment | Confirm that control owners will perform recurring activities and retain evidence. |
Translate ISO 27001 into six management system pillars
ISO 27001 is scalable. The management system, risk process and controls should reflect the organization, its obligations, operating model and threat exposure.
01 Context and scope
Define the business environment, interested parties, obligations, boundaries and interfaces.
02 Leadership and governance
Approve policy, assign authority, provide resources and hold management accountable.
03 Planning and risk
Assess risk, choose treatments, define objectives and plan controlled change.
04 Support and operation
Provide competence, communication, controlled information and repeatable control activity.
05 Performance evaluation
Monitor objectives, assess controls, complete internal audit and management review.
06 Improvement
Correct nonconformities, address root causes and improve suitability and effectiveness.
Requirement area
| Requirement area | Practical meaning for an SME |
|---|---|
| Clause 4 | Context, interested parties, ISMS scope and management system requirements. |
| Clause 5 | Leadership commitment, policy, authorities and responsibilities. |
| Clause 6 | Risk and opportunity planning, risk treatment and measurable objectives. |
| Clause 7 | Resources, competence, awareness, communication and controlled information. |
| Clause 8 | Operational planning, risk assessment, risk treatment and change control. |
| Clause 9 | Monitoring, measurement, internal audit and management review. |
| Clause 10 | Nonconformity, corrective action and continual improvement. |
Climate relevance
- Determine whether climate change is relevant to organizational context and whether interested parties have related requirements.
Common misconception
- Policies alone do not prove conformity. Auditors expect implementation, operating records, review and corrective action.
Annex A
- Annex A is a reference set. Applicability is determined through risk treatment and recorded in the Statement of Applicability.
Move from decision to certification through six readiness gates
The sequence matters more than the calendar. Scope and risk decisions should precede control selection, and operating evidence should precede internal assurance.
Exhibit 1: Readiness gate model
- Mobilize: sponsor, ISMS lead, resources and delivery governance.
- Scope: context, interested parties, obligations, boundary and interfaces.
- Assess risk: criteria, scenarios, owners, ratings and treatment priorities.
- Design controls: treatment plan, Statement of Applicability and implementation owners.
- Operate: routine activity, current records, monitoring and exception handling.
- Assure: internal audit, management review, corrective action and certification.
Each gate requires an approved output and a clear decision to proceed.
Decision rule
- Do not move forward because a calendar date has arrived rather than because the gate output has been approved.
Timing reality
- A focused SME scope may be prepared in a compressed timeframe if leadership decisions are made promptly.
Common trap
- Scheduling a certification audit before scope, risk and evidence are genuinely ready.
Show what is included and how material external dependencies are governed
The certification boundary should describe the services, information, people, technology, suppliers and interfaces that make up the ISMS, along with the dependencies and interfaces that sit around it.
Exhibit 2: Scope boundary view
- Inside the ISMS boundary - Services: products and business processes covered by certification.
- Inside the ISMS boundary - Information: customer, employee, operational and intellectual property data.
- Inside the ISMS boundary - Technology: applications, cloud services, networks, devices and platforms.
- Inside the ISMS boundary - People and locations: roles, teams, offices and remote operating arrangements.
- Dependencies and interfaces - Suppliers: cloud, software, support, payment and specialist providers.
- Dependencies and interfaces - Shared services: corporate identity, finance, human resources and facilities.
- Dependencies and interfaces - Customers and partners: contractual requirements, access routes and information exchanges.
- Dependencies and interfaces - External obligations: laws, regulation, contracts and sector expectations.
Minimum foundation pack
- Scope statement
- Boundary view
- Security policy
- Objectives and measures
- Governance model
- Evidence repository
Scope warning
- Do not use certification scope to hide risk. Legitimate exclusions still require management of material dependencies and interfaces.
Good scope wording
- Describe the certified service, location, delivery model and relevant technology in language that customers and auditors can understand.
Foundation decisions
| Decision | Management question | Minimum evidence |
|---|---|---|
| Certification objective | Why does certification matter? | Approved business case and success measures. |
| Scope boundary | Which services, people, systems, information and suppliers are included? | Scope statement and boundary view. |
| Context and obligations | Which market, legal, contractual and threat factors matter? | Context and obligations register. |
| Governance | Who sponsors, owns risk, operates controls and audits? | Governance charter and responsibility model. |
Make the risk process the engine of the ISMS
The risk assessment should explain why controls were selected and where management accepted residual exposure. It should be repeatable, understandable and connected to business services and information.
Exhibit 3: Risk treatment lifecycle
- Set criteria: define likelihood, impact, acceptance thresholds and decision authority.
- Identify scenarios: connect services and information to threats, weaknesses and consequences.
- Assess and own: assign inherent risk, existing controls, effectiveness and a risk owner.
- Treat and accept: avoid, modify, share or retain risk through approved decisions.
- Monitor and review: track incidents, changes, failed controls, overdue actions and review triggers.
Risk record fields
| Field | Expected content |
|---|---|
| Risk statement | Cause, event and business impact tied to an in scope service or information asset. |
| Ownership | Accountable risk owner and parties required to implement treatment. |
| Risk ratings | Inherent and residual assessments using the approved method and criteria. |
| Controls and gaps | Current controls, evidence, effectiveness and weaknesses. |
| Treatment action | Specific action, owner, target date, dependency and success measure. |
| Acceptance and review | Authorized residual decision and defined reassessment trigger. |
Statement of applicability
- For each Annex A control, record applicability, justification, implementation status, ownership and evidence source.
Weak practice
- Copying all Annex A controls into a spreadsheet without connecting them to risk treatment or actual operation.
Decision test
- Can management explain why each material control is included, excluded or planned?
Turn selected controls into repeatable practices and audit ready evidence
Implementation is complete only when activities are assigned, performed, recorded, reviewed and improved. Existing operational workflows should be reused wherever possible.
Exhibit 4: The evidence pattern auditors expect
- Design: a requirement, procedure or configured control defines what should happen.
- Operate: the accountable owner performs the control in normal work.
- Record: an artifact shows what occurred, when, by whom and with what result.
- Review: exceptions, failures and trends are assessed and escalated.
- Improve: corrective actions address root cause and are checked for effectiveness.
- Retain: records remain protected, searchable, attributable and available.
Governance and documents
Policy approval, document control, objectives, exceptions and risk acceptance.
People and access
Onboarding, awareness, role change, offboarding and access review.
Technology operations
Secure configuration, vulnerability management, logging, change and backup.
Data and suppliers
Classification, retention, encryption, cloud assurance, contracts and exit planning.
Incident and continuity
Reporting, response, lessons, continuity plans and recovery testing.
Physical and workplace
Site access, visitor management, equipment protection and secure disposal.
Document hierarchy
| Level | Purpose | Example |
|---|---|---|
| Policy | Management direction and mandatory principles. | Information security policy. |
| Standard | Specific minimum requirements that can be tested. | Authentication, logging and backup. |
| Procedure | How assigned roles perform a process. | Incident response and risk assessment. |
| Record | Proof that the process or control operated. | Tickets, logs, minutes and test results. |
Evidence quality
- Current
- Attributable
- Complete
- Protected
- Retrievable
Common failure
- A procedure exists, but no owner can demonstrate that the activity occurred at the required cadence.
Control owner test
- Can the owner show the latest record, explain exceptions and describe what happens when the control fails?
Build a lean operating rhythm that keeps the ISMS current
A growing organization does not need a large compliance department. It needs clear owners, reliable recurring activities and a management cadence that converts evidence into decisions.
Roles and accountabilities
| Role | Core accountability | Primary value |
|---|---|---|
| Executive sponsor | Approves scope, policy, resources, objectives and material risk decisions. | Leadership and authority. |
| ISMS lead | Coordinates implementation, evidence, meetings, actions and certification activity. | Programme integration. |
| Risk owners | Assess business impact and approve treatment and residual risk. | Business accountability. |
| Control owners | Operate controls, retain evidence, report failure and complete remediation. | Operational effectiveness. |
| Internal auditor | Tests conformity and effectiveness independently and reports findings. | Objective assurance. |
| External adviser | Provides methods, challenge and specialist support without owning decisions. | Independent expertise. |
Recommended management cadence
| Cadence | Management purpose |
|---|---|
| Weekly delivery review | Track actions, dependencies, decisions and evidence gaps. |
| Monthly risk review | Review material risk, overdue treatment and residual decisions. |
| Monthly control review | Assess implementation, evidence freshness, exceptions and failures. |
| Quarterly objective review | Review performance against security objectives and business outcomes. |
| Planned management review | Evaluate suitability, adequacy, effectiveness, changes and resource needs. |
Lean does not mean informal
- Combined roles can work when approvals, independent review and management oversight remain clear.
Independence warning
- The person who designed or operates a control should not be the only person assessing its effectiveness.
Evidence repository
- Organize records by requirement, control, owner, period and review status so evidence can be retrieved quickly.
Operating principle
Every recurring activity should have an owner, defined cadence, evidence source, escalation route and review expectation.
Test the ISMS before the certification body does
Internal audit and management review are the organization's final opportunity to identify weakness, confirm leadership decisions and demonstrate that the ISMS can correct its own failures.
Exhibit 5: Assurance and improvement loop
- Internal audit: test conformity and effectiveness across the full scope with sufficient independence.
- Management review: evaluate performance, changes, resources, risk, objectives and improvement opportunities.
- Corrective action: contain the issue, identify root cause, assign action and define expected results.
- Effectiveness review: confirm that correction addressed the cause and reduced recurrence.
Readiness gate and evidence of readiness
| Readiness gate | Evidence of readiness |
|---|---|
| Full scope internal audit | The audit covers applicable clauses, controls, locations, processes and interfaces. |
| Management review | Leadership reviews performance, changes, resources, risks and improvement opportunities and records decisions. |
| Corrective action | Nonconformities are contained, root causes assessed, actions assigned and effectiveness checked. |
| Traceability | Scope, obligations, risks, treatment, Statement of Applicability, controls and evidence tell one story. |
| Operational awareness | Relevant personnel can explain responsibilities and demonstrate how controls work. |
| Evidence availability | Records can be retrieved promptly and are protected from inappropriate alteration or loss. |
Internal audit question
- Is the organization doing what it said it would do, and is that approach producing the intended result?
Weak corrective action
- Updating a document without addressing why the process failed or why the issue was not detected earlier.
Management review output
- Recorded decisions on improvement, changes, resources, objectives and treatment of material risk.
Prepare for an independent certification decision
Certification provides independent assurance that the management system conforms to the standard. ISO develops the standard but does not certify organizations.
Exhibit 6: Certification pathway
- Select the body: assess competence, scope, approach, timing and accreditation status.
- Stage 1: review ISMS design, documentation and preparedness for Stage 2.
- Close concerns: address issues that could prevent an effective Stage 2 audit.
- Stage 2: evaluate implementation and effectiveness across the approved scope.
- Maintain: continue surveillance, risk review, audit, management review and improvement.
Governance
Approved scope, policy, objectives, role assignments and governance records.
Context and obligations
Interested parties, internal and external issues, and legal and contractual requirements.
Risk and control traceability
Risk method, current register, treatment plan and Statement of Applicability.
Operating evidence
Core procedures, monitoring, internal audit, management review and corrective action.
Certification body selection
| Consideration | What to confirm |
|---|---|
| Competence | Experience with the organization's sector, technology and intended scope. |
| Commercial terms | Stage 1, Stage 2, surveillance, travel, additional time and certificate maintenance costs. |
Certification fact
- ISO does not issue certificates. External certification bodies conduct audits and issue certification decisions.
Do not schedule too early
- Stage 1 should not become a substitute for the organization's own readiness assessment.
Build momentum through three focused implementation waves
Sequence the first ninety days into mobilize, assess and implement, and operate and assure, so leaders reach certification readiness with clear evidence.
Days 0 to 30: mobilize and baseline
- Name the sponsor, ISMS lead, risk owners and control owners.
- Approve the initial scope and certification objective.
- Complete context, interested parties and obligations.
- Run a gap assessment and establish the evidence repository.
- Agree risk criteria and reporting cadence.
Days 31 to 60: assess and implement
- Complete risk assessment and risk treatment.
- Approve the Statement of Applicability.
- Assign implementation owners and due dates.
- Close priority governance and control gaps.
- Begin routine evidence collection.
Days 61 to 90: operate and assure
- Run recurring risk, control and objective reviews.
- Test incident and continuity procedures.
- Complete internal audit and management review.
- Close material corrective actions.
- Decide whether certification planning can proceed.
Success indicators
- Approved scope
- Current risk register
- Approved Statement of Applicability
- Named control owners
- Operating evidence
- Internal assurance plan
Delivery principle
Every action needs an accountable owner, a clear due date, a decision path and evidence that demonstrates completion.
Delivery cadence
| Cadence | Management purpose |
|---|---|
| Weekly delivery review | Track actions, dependencies, decisions and evidence gaps. |
| Monthly risk review | Review material risk, overdue treatment and residual decisions. |
| Monthly control review | Assess implementation, evidence freshness, exceptions and failures. |
| Readiness decision | Proceed only when design, operation and assurance gates are met. |
Management outcome
- By day ninety, leaders should have clear visibility of scope, risk, control status, evidence gaps and certification readiness.
ISO 27001 readiness checklist for SMEs
Use this checklist to confirm that minimum governance, risk, control, evidence and assurance components are implemented and operating. A checked box should mean more than a document exists.
Readiness checklist
| Readiness area | Minimum evidence |
|---|---|
| Leadership | Sponsor, ISMS lead, risk owners and control owners are named. Policy and objectives are approved. |
| Scope | The boundary, sites, services, systems, people, suppliers and interfaces are documented. |
| Context and obligations | Internal and external issues, interested parties, legal and contractual requirements are current. |
| Risk method | Likelihood, impact, acceptance criteria, authority and review triggers are defined. |
| Risk register | Material scenarios have owners, ratings, treatment dates and residual decisions. |
| Statement of Applicability | Applicability, justification, status, owners and evidence align with treatment. |
| Control operation | Priority organizational, people, physical and technology controls are repeatable. |
| Evidence | Records are authentic, current, attributable, retrievable and appropriately retained. |
| Performance | Objectives, failures, incidents, supplier issues and progress are reviewed. |
| Internal audit | The full scope and applicable requirements have been independently audited. |
| Management review | Leadership reviewed the ISMS and recorded decisions on resources and change. |
| Corrective action | Material nonconformities are corrected and checked for effectiveness. |
Evidence test
- Can the organization retrieve a current, attributable record that proves the activity operated as designed?
Gap treatment
- Where evidence is incomplete, record the gap, business impact, owner, target date and interim risk treatment.
Decision test
- Is there a named owner, defined response and escalation path when performance deteriorates?
Reference sources and publication scope
The references below provide the basis for the management system, risk, control and certification concepts used in this brief. Requirements should still be interpreted for the organization's own context.
- ISO/IEC 27001:2022. Information security management systems requirements. Published October 2022.
- ISO/IEC 27001:2022 Amendment 1:2024. Climate action changes. Published February 2024.
- ISO/IEC 27002:2022. Guidance for information security controls.
- ISO/IEC 27005:2022. Guidance on managing information security risks.
- ISO certification guidance. ISO guidance on certification and selecting a certification body.
- ISO/IEC 27006 1:2024. Requirements for bodies providing audit and certification of information security management systems.
How to use this brief
- Use it as a management roadmap, then tailor scope, risk criteria, controls, evidence and assurance to the organization.
Certification caveat
- Certification scope and audit conclusions are determined by the selected certification body and the evidence available.
About this advisory
This publication provides general information and does not constitute legal, regulatory, certification or other professional advice. Requirements should be tailored to the organization's context, jurisdiction, intended scope and risk profile.
