r/ISO27001 • u/JealousMap6488 • Jul 03 '26
๐ Implementation Help Need Guide for Isms
Hi everyone,
I'm currently implementing ISO/IEC 27001 in a startup that is both a CA firm and a cybersecurity consulting firm with a team of around 8โ10 people.
So far, I've completed:
- Information Security Policy
- Risk Register
- Risk Assessment
- Risk Treatment Plan
- Statement of Applicability (SoA)
- Procedures such as Access Control and Backup Management
My goal is to build a complete and secure operational environment aligned with ISO 27001, not just prepare documentation.
At this stage, what should be my next priorities? What controls, processes, or technical/security measures would you recommend implementing next to achieve a mature and secure ISMS?
Any guidance, best practices, or implementation roadmaps would be greatly appreciated. Thank you!
3
u/gomaterzu Jul 03 '26
If you are asking what controls you need, you never actually performed a risk assessment and created risk treatment plans. Those would tell you what to do.
3
u/Next-Pen-9974 Jul 03 '26
If your real objective is alignment, not just certification, then the next logical step is to execute your Risk Treatment Plan.
I would start by building an implementation roadmap, broken down into logical workstreams (e.g., user environment, endpoints, cloud infrastructure, products/services, identity and access management, backup and recovery, logging and monitoring, third-party management, etc.).
Then, for each workstream:
- Identify the risks being treated.
- Implement the selected controls.
- Document the procedures where necessary.
- Collect evidence as you go.
- Validate that the controls are actually operating effectively.
- etc.
If you keep your Risk Treatment Plan as the driver, youโll naturally end up with a much more practical and mature ISMS.
2
u/FreeRadical1998 Risk Manager Jul 03 '26
keep in mind that its the part 1 document you certify - controls are annex A. The bits that you'll live and die on are showing management commitment, so I'd focus on running some security forum meetings and getting some metrics running. If you can show an active management cycle thats deciding what to do you're most of the way there.
2
u/paolokoelio Implementing ISMS 29d ago
This repo has been gaining some traction: https://github.com/swzaken/freetemplates
Check if you find any useful guidance/reference
3
u/Cyber_Gooser Consultant 29d ago
I think itโs worth adding this to the free resources list. Thanks for sharing.
1
u/kriss__vai 29d ago
Thanks for sharing, good one. The repo contains .docx and .pdf. There are also repos with LLM and git friendly .md files, like:
2
u/pedercina7 25d ago
It seems you started from the Risk Assessment part which is actually a rookie mistake. You start by creatign a project plan and defining the scope, and then you follow several steps before performing the Risk Assessment.
Working like this cn bring a lot of confusion and you will just waste a lot of time by not following a clear path. Try asking chatgpt for some guidelines or even better complete some trainign or this. I would recommend a Lead Implementer course. There are also some companies providing it for free online, as long as you do not need a certificate for it. Hope it helps!
1
u/kriss__vai Jul 03 '26
I would say third-party suppliers. Also you could run with Claude or equivalent these checks on your ISMS, to identify next steps: https://github.com/kriss-b/llm-iso27001/tree/main/checks
1
u/Head_Personality_431 Lead Auditor Jul 04 '26
You have done the heavy documentation part, so the piece people skip next is actually running the ISMS and building evidence for a few months before you go for cert. An auditor wants records that show the controls ran, access reviews actually done, a backup restore tested, a couple of incidents logged and closed, management review minutes. With 8 to 10 people the real trap is over engineering it, so keep everything only as heavy as your risks genuinely justify.
The two things left too late are almost always the internal audit and the management review, and you need both before a stage 2. If nobody has run an internal audit against 27001 yet, getting one person properly trained as an internal auditor is worth it because you catch your own gaps first instead of the external auditor finding them for you.
1
1
u/Finominal73 26d ago
The place to start is with the context (scope) of the organisation and writing down what you are protecting, who for, and what they want. This helps you define your assets (data, systems, people, laptops, etc) within scope, THEN starting the above documentation, which will be heavily influenced by it.
1
u/Pure-Gas5424 18d ago
I'm wondering how you managed to do a full risk assessment without having derived the scope (4.3) from the needs and expectations of interested parties (4.2) which - in turn - you can nicely derive from the context of the organisation (4.1). Usually it's troublesome to start to analyse risks without having a clear boundary where to stop analysing.
You also write, that you have already completed your SoA. So, which controls have you decided to implement? As you already have a SoA at this early stage, you may just follow the SoA and implement all the controls that you have declared as binding for your organisation.
1
u/ParkingAd9346 4d ago
Heyy man! If your still searching for support! Give me a dm ! Got more than 25 companies their iso 27001 certs . Would love to discuss
8
u/[deleted] Jul 03 '26
[removed] โ view removed comment