Establish purpose, context and scope
The ISMS scope determines which business services, locations, systems, interfaces and dependencies are genuinely governed. An excessively broad scope can overwhelm the programme; an artificially narrow scope can hide material risks and interfaces.
Assumptions, boundaries and exclusions therefore require a defensible rationale, named ownership and management approval.
- Business services and information assets in scope
- Relevant internal and external interested parties
- Technical, organisational and contractual interfaces
Set governance and the risk method
Roles, risk acceptance, escalation and reporting routes should be established before detailed control work begins. Otherwise, the programme produces action lists without decision capability.
Assessment criteria should be consistent, repeatable and understandable to management. Apparent numerical precision cannot replace transparent reasoning or the treatment of uncertainty.
Derive controls and the Statement of Applicability
Controls follow from risk, obligations and operational context; Annex A is not a shopping list. Each relevant control should connect its objective, owner, implementation state and dependable evidence.
The Statement of Applicability then becomes a steering artefact rather than a spreadsheet completed immediately before an audit.
Move the ISMS into operational cadence
A management system operates through recurring control activities, awareness, metrics, internal reviews and management review. Policies alone do not demonstrate effectiveness.
Evidence should arise from daily operation: tickets, approvals, records, risk decisions, technical systems and traceable reviews.
- A control calendar with named owners
- A defined decision and escalation cadence
- Corrective actions with target states and effectiveness checks
Assess readiness and prepare for external audit
Internal review, management review and corrective-action processes must operate before the certification date. Unresolved gaps should be recorded transparently and managed through realistic plans.
Audit preparation improves the availability and quality of evidence. It does not replace an independent audit opinion or guarantee certification.
Service boundary
Services include ISMS development, readiness, gap assessment, audit preparation and professional support. Independent audits, conformity opinions and certification decisions remain solely with the appointed audit or certification body.