Start with scope, not templates
The fastest way to create unnecessary work is to copy a large policy set before deciding what the ISMS covers. Begin with the services, locations, people, technology, information and third parties that support the intended certification scope. A 50–100 employee organisation can remain focused without excluding dependencies that materially affect risk.
Phase 1: Mobilise and define the ISMS
- Name an executive sponsor and an implementation owner.
- Document organisational context, interested parties and the proposed scope.
- Agree security objectives, reporting cadence and decision forums.
- Create a controlled action tracker and evidence repository.
Phase 2: Assess risk and applicability
Inventory important information assets and business processes, define consistent likelihood and impact criteria, then record risks in business language. Treatment decisions determine which controls are necessary. The Statement of Applicability should explain inclusion, exclusion and implementation status; it should not be a copied checklist.
Phase 3: Implement priority controls
Prioritise controls that reduce material risk and produce repeatable evidence: identity lifecycle, privileged access, secure configuration, vulnerability management, backups, logging, incident response, supplier governance and change management. Assign one accountable owner per control even when several teams contribute.
Phase 4: Operate and collect evidence
Auditors need evidence that the management system operates. Run access reviews, vulnerability cycles, incident exercises, supplier reviews, backup tests and management reporting. Record exceptions and corrective action instead of attempting to present a perfect environment.
Phase 5: Internal assurance
- Conduct an internal audit with enough independence from the work being assessed.
- Record findings and complete root-cause-oriented corrective actions.
- Hold management review using performance, incidents, objectives, audit results, risks and improvement decisions.
- Confirm scope, controlled documentation and evidence accessibility before the external assessment.
Common implementation mistakes
- Making the scope so broad that ownership and evidence become unmanageable.
- Treating Annex A as the complete standard and overlooking management-system requirements.
- Buying technology before understanding risk and operating responsibility.
- Writing policies that do not match actual practice.
- Waiting until the audit to discover missing evidence.