Blog
Blog

Risks under control: an ISMS based on ISO/IEC 27001

ISMS Framework 17 October 2024 By fortControl Editorial Team

Information security is not made up of firewalls, passwords and isolated technical measures. What matters is that a company knows its information risks, defines responsibilities and manages security measures systematically.

That is exactly the framework an information security management system – ISMS for short – provides.

ISO/IEC 27001 is the internationally established standard for building, operating and continually improving an ISMS. Companies can use the standard as a point of orientation without seeking certification – or as the basis for later external certification.

Either way: a good ISMS should not make information security more complicated. It should make it manageable.

What exactly is an ISMS?

Companies process information every day without which their business processes would barely function: customer data, contracts, financial information, technical documentation, credentials, HR data or internal know-how.

This information has to be protected appropriately.

Three fundamental protection goals are involved: confidentiality, integrity and availability. Information should be accessible only to authorised people, remain correct and unaltered, and be available when it is needed.

An ISMS creates a systematic framework for this. Among other things, it defines how information security risks are identified and assessed, which measures are necessary, who is responsible, and how it is verified whether the precautions taken actually work.

The decisive difference compared to individual security projects lies in continuity. Information security is not a project with an end date.

Companies, technologies, threats and regulatory requirements change constantly. An effective ISMS therefore evolves along with the organisation.

Why ISO/IEC 27001?

ISO/IEC 27001 is one of the most widely recognised international standards for information security management. The standard sets out requirements an ISMS has to meet and takes a risk-based approach.

This means that not every company has to implement the same security measures everywhere. A small service company faces different risks than an industrial company with production facilities, a financial services provider or a critical infrastructure operator.

The first question is therefore decisive: which information, processes and systems are relevant for our company – and which risks are they exposed to?

Appropriate measures are derived from this analysis.

Ideally, ISO/IEC 27001 thereby prevents exactly what often happens in practice: companies invest heavily in individual security solutions without first clarifying sufficiently which risks actually have to be addressed first.

  1. 1 Define context and scope Clarify relevant processes, information and requirements, and define the scope.
  2. 2 Establish accountability at management level Management support, clear roles, resources and information security objectives.
  3. 3 Assess and treat risks Identify and assess information security risks and decide on them transparently.
  4. 4 Determine security controls Derive controls from risk treatment and compare them with Annex A, documented in the SoA.
  5. 5 Implement measures and live them Embed technical and organisational measures in day-to-day work — employees included.
  6. 6 Monitor, measure and review Assess effectiveness, use meaningful metrics, carry out internal audits.
  7. 7 Management review and improvement Management evaluates the ISMS, and findings lead to new decisions.

The findings feed back into context, risks and measures: an ISMS is never really finished.

The path to an ISMS based on ISO/IEC 27001 in seven steps.

Step 1: define context and scope

Before policies are written or security measures selected, it has to be clear which area the ISMS is intended to cover. To do this, the company looks at its internal and external context.

Which business processes are particularly relevant? Which information has to be protected? Which legal, regulatory and contractual requirements apply? What do customers, owners, partners or other interested parties expect?

On this basis, the scope of the ISMS is defined. It can cover the entire company or, for example, specific legal entities, sites, business units, services or products.

A clearly defined scope is especially decisive if certification is sought later on. Because an ISO/IEC 27001 certification always refers to the defined scope – not automatically to all activities of a company.

Step 2: establish accountability at management level

An ISMS does not work as an isolated project of the IT department.

Information security affects business processes, employees, suppliers, infrastructure, applications and strategic decisions. An effective management system therefore requires clear anchoring within the organisation.

Management has to support information security, define responsibilities and provide the necessary resources. This also includes information security objectives that fit the company’s strategic direction.

The reason is simple: where accountability is unclear, security measures often remain non-binding.

An effective ISMS therefore answers not only the question of what has to be done, but also: who decides? Who implements? Who reviews? And who ultimately bears responsibility?

Step 3: assess and treat information security risks

Risk management forms a central part of the ISMS.

First, relevant information security risks are identified and assessed against defined criteria. This concerns, for example, the possible impact of a system outage, unauthorised access to sensitive information, the loss of data, dependencies on service providers or risks arising from human error.

Then a decision has to be made on how to deal with the identified risks. A risk can, for example, be reduced, avoided, transferred or deliberately accepted.

What matters is that these decisions are not made purely intuitively. Risks, assessments and decisions have to be traceable.

This creates a basis on which the organisation can deploy its security resources where action is most needed.

Step 4: determine security controls

Only now does the question of concrete security measures arise.

In Annex A, ISO/IEC 27001 contains 93 reference controls from organisational, people, physical and technological domains. These cover topics such as access control, information security policies, supplier relationships, backup, logging, secure development, incident management and business continuity.

It is important to note, however, that Annex A is not a checklist in which every company simply ticks off every point. The necessary controls are determined on the basis of risk treatment and then compared with Annex A so that relevant security areas are not overlooked.

The Statement of Applicability – SoA for short – plays a central role here. It documents which controls are relevant for the ISMS, which are implemented, and why certain reference controls may not be applicable.

This turns a long collection of possible security measures into a security concept tailored to the organisation.

Step 5: implement measures and live information security

An ISMS does not come into being by writing policies. The defined measures have to work in everyday practice.

This can concern technical measures such as multi-factor authentication, backup or logging. Organisational topics are just as important, however: roles and responsibilities, supplier management, training, joiner and leaver processes or the handling of security incidents.

Employees also play a central role. They have to know which requirements apply to them and why they matter. Information security should therefore not be communicated just once a year through awareness training, but be part of daily business practice.

Because an ISMS that only exists in policies and documents does not fulfil its actual purpose.

Step 6: monitor, measure and review

The real management task begins after implementation.

Do the defined processes work? Are measures being followed? Are we achieving our information security objectives? Where are new risks emerging? Which measures are overdue or ineffective?

Answering these questions requires suitable monitoring and measurement methods. Metrics can help here.

What matters, however, is not producing as many KPIs as possible. Good metrics provide information from which decisions can be derived. For an SME, a few meaningful metrics can be more valuable than extensive reporting that creates a lot of effort but hardly delivers information relevant to steering.

Internal audits are another important component. They systematically verify whether the ISMS meets the company’s own requirements and those of the standard, and whether it is effectively implemented.

Step 7: management review and continual improvement

Information security is also a management task. ISO/IEC 27001 therefore provides for a regular evaluation of the ISMS by management.

The management review considers, for example, changes in the business environment, audit results, developments in risks, information security objectives, security incidents and opportunities for improvement.

This closes the loop. Findings lead to new decisions and measures. Risks are adjusted, controls improved and processes developed further.

A good ISMS is therefore never really finished. And that is precisely its strength. It ensures that information security keeps pace with the company and its risks.

Top-down or a pragmatic start?

Not every company has to introduce an ISMS in the same way.

A classic top-down approach starts with governance, scope, policies, responsibilities and an overarching framework. The processes and measures are then implemented systematically. This creates clear structures from the outset, but can initially feel abstract and extensive, particularly for smaller organisations.

A pragmatic, iterative approach starts more from concrete challenges – for example a risk assessment, a security assessment or the introduction of structured measure management – and gradually develops further components of the ISMS from there. This procedure can make sense for SMEs in particular, because visible results emerge early.

Here, too, the following applies: bottom-up only works in the long term with top-down support. Without clear accountability from leadership, resources and binding decisions, there is a risk that individual security activities emerge but no permanently effective management system.

The most sensible route therefore often lies in a combination: clear support from management alongside pragmatic, step-by-step implementation.

What does an ISMS bring to the company?

The benefit of an ISMS goes far beyond producing policies or passing an audit. Above all, a well-functioning ISMS creates transparency.

The company knows which information risks are relevant, which measures are in place against them, who is responsible and where action is still required.

This brings further advantages: regulatory and contractual requirements can be handled in a more structured way, responsibilities become clearer, security investments can be prioritised better and customer requirements answered more transparently.

Information security also plays an increasing role in tenders and supply chains. An established ISMS can therefore not only reduce risks, but also build trust and make business relationships easier.

ISO/IEC 27001: certification or best practice?

Not every company that follows ISO/IEC 27001 has to be certified. The standard can be used as an internationally established framework to build and develop information security management systematically.

For some companies this approach is sufficient. Others need external certification – for example because of customer requirements, tenders, contractual obligations or their own market positioning.

Certification confirms, through an independent certification body, that the ISMS meets the requirements of the standard within the stated scope. It is worth paying attention to the certification body as well. Accreditation offers additional independent confirmation of its competence.

Certification requires effort and resources. It should therefore not be pursued simply because a certificate looks good. The better question is: what concrete benefit does certification bring us?

If the answer is clear, it can be a valuable additional piece of evidence.

How fortControl supports building an ISMS

As an ISMS matures, so does the volume of information that has to be managed. Risks, assessments, measures, responsibilities, controls, evidence, review dates and improvements are all related to one another.

Anyone who spreads this information across numerous Excel files, documents and emails quickly loses the overall picture.

fortControl helps companies bring the central elements of an ISMS together in a structured way. Risks can be assessed and linked to measures. Responsibilities and deadlines become visible. Assessments and controls can be worked on in a structured way and developments can be traced.

This creates a shared information base for subject matter owners, information security and management.

Here, too, the following applies: a tool does not build an ISMS on its own. But a good tool can ensure that individual documents and activities become a traceable, continuously manageable process.

Information security becomes effective when it becomes manageable

ISO/IEC 27001 gives companies an established framework for organising information security systematically. But the real value of an ISMS does not come from the standard, nor from a certificate.

It comes when a company knows its risks, makes clear decisions, takes on responsibilities and can verify whether its measures work.

Identify risks. Set priorities. Implement measures. Verify effectiveness. Improve.

That is when information security becomes more than a collection of individual technical and organisational measures. It becomes an integral part of running the company.

Loslegen

Risiken im Blick. Sicherheit im Griff.

Lernen Sie fortControl in einer persönlichen Demo kennen.

fortControl – Risikomanagement und Informationssicherheit einfach steuern.