Building an ISMS, Step-by-Step to ISO 27001
Introduction
Building an ISMS is not a documentation project, it is a change in the operating model. The failed programmes we are asked to rescue typically show two symptoms: a complete policy stack with no visible effect in daily operations, and a risk analysis that nobody on the front line understands. The reason is almost always a missing, step-by-step roadmap. ISO/IEC 27001:2022 requires clauses 4–10 to be implemented in a specific order; pulling steps forward only creates rework loops.
We present a 12-step roadmap that has been proven in Swiss SMEs and mid-market companies for over a decade. It covers:
- Initialisation, scoping, stakeholder mapping
- GAP analysis against all 93 Annex A controls and clauses 4–10
- Risk methodology, risk assessment, risk treatment plan and SoA
- Policy stack, awareness and operational control implementation
- Internal audit, management review, preparation for Stage 1 and Stage 2
The duration varies by maturity, but the sequence is robust. Each step produces artefacts that the auditor will later want to see in concrete form. At the end of each section we name the artefact or evidence that emerges.
Steps 1 to 3, Initialisation, scope, stakeholders
Step 1, Project set-up: executive sponsor, dedicated project lead (ISO officer), budget, timeline, communication plan. We recommend a 12 to 14 month initial cycle with bi-weekly steering and a documented kick-off charter. Artefact: charter and RACI matrix.
Step 2, Scope (clause 4): which business units, sites, subsidiaries, cloud tenants and products belong to the ISMS? In SaaS companies we recommend starting with the product stack and the engineering team, that is the substance of the customer promise, and bringing marketing, sales and HR in the following year. A contextual scope statement with inclusions and exclusions is mandatory documentation. Artefact: scope statement.
Step 3, Stakeholders and requirements (clause 4.2): customers, supervisors (FDPIC, FINMA, FOPH), investors, employees, suppliers, each stakeholder group brings its own requirements (industry standards, contracts, laws). This requirements list is refreshed in the annual management review and feeds the risk assessment. Artefact: stakeholder register including compliance obligations.
Steps 4 and 5, GAP analysis and risk methodology
Step 4, GAP analysis: a maturity assessment per control (0 = absent, 1 = ad hoc, 2 = documented, 3 = implemented, 4 = measured, 5 = optimised). We assess all 93 Annex A controls and clauses 4–10. The output is a colour-coded view that shows the steering committee where to invest. In most SMEs we start with an average maturity of 1.5 and need to reach at least 3.0 for a successful certification audit. Artefact: GAP report with roadmap.
Step 5, Define the risk method (clause 6.1.2): asset-based, scenario-based or process-based? For ISMS first projects a hybrid works best: process-based (each business process is examined once), with an asset-based deep-dive for the crown-jewel systems. Risk scales (3×3 or 5×5) must be defined before the risk assessment, otherwise the scale will be adjusted to the desired risk profile after the fact, a classic audit finding. Artefact: risk methodology document including acceptance criteria.
Steps 6 and 7, Risk assessment, SoA, risk treatment
Step 6, Risk assessment and SoA (clause 6.1.3 / Annex A): the risk assessment produces the risk register. From the register comes the risk treatment plan, where every significant risk is decided: avoid, reduce, transfer or accept. From this the Statement of Applicability (SoA) is derived, a list of all 93 Annex A controls with applicability (yes/no), justification and current implementation status. The SoA is the single most-examined document in audits and must be versioned. Artefact: risk register, risk treatment plan, SoA v1.
Step 7, Security objectives and policies (clauses 6.2 / 5.2): measurable objectives are derived from the risks and the stakeholder register (for example, ‘phishing click rate below 5%’, ‘100% patch coverage of critical systems within 14 days’). The information security policy itself is a concise two-page document signed by the executive board. Below that, a modular policy stack (12 to 18 topic policies, depending on complexity): acceptable use, access control, cryptography, backup, incident response, supplier security and so on. Artefact: policy library, KPI set.
Steps 8 and 9, Control implementation and awareness
Step 8, Operational control implementation (clause 8 / Annex A): the risk treatment plan becomes a backlog of measures, delivered in sprints (or, in classical project setups, in milestones). Typical priorities:
- IAM and MFA (A.5.16, A.5.17, A.8.5)
- Logging and monitoring (A.8.15, A.8.16)
- Backup and recovery (A.8.13)
- Vulnerability management and patching (A.8.8)
- Supplier security and DPAs (A.5.19–A.5.22)
- Incident response and crisis communication (A.5.24–A.5.27)
Tooling decisions (SIEM, EDR, MDM, IAM, GRC) are taken in this phase, not earlier, otherwise you buy without requirements. Artefact: implemented controls with evidence.
Step 9, Awareness and training (clauses 7.2 / 7.3): mandatory onboarding for new joiners, annual refresher, role-based deep dives for IT, engineering, HR and sales. Phishing simulations at least twice per year. Without documented participation rates above 95%, the auditor will follow up. Artefact: training plan and completion records.
Steps 10 and 11, Internal audit and management review
Step 10, Internal audit (clause 9.2): before the certification audit, at least one full internal audit following an audit programme must be completed. The auditor must be independent of the audited area, in smaller organisations that means in practice: an external auditor or a colleague from another function with no operational ties. The audit checks both the standard and the internal policies. Findings are classified as major, minor or observation and accompanied by corrective actions.
Step 11, Management review (clause 9.3): at least once per cycle, top management convenes against a defined agenda: status of previous reviews, changes in internal and external issues, KPI achievement, internal and external audit findings, incidents, risks, improvement opportunities, resource needs. The minutes are signed by the CEO or COO. In audits, this record is the second-most important document after the SoA. Artefact: internal audit programme, audit reports, management review minutes with decisions.
Step 12, Stage 1 and Stage 2 audit
Stage 1 (document review / readiness assessment): the certification body examines the documented information, primarily scope, risk methodology, risk register, SoA, internal audit programme, management review minutes. The usual output is a list of ‘areas of concern’ to be addressed before Stage 2. Stage 1 in SMEs takes 1 to 2 person-days and can be conducted remotely. It is the opportunity to understand where the actual auditor will focus during Stage 2.
Stage 2 (implementation audit): on-site or hybrid audit, typically 3 to 6 person-days depending on size. The audit tests effectiveness, through interviews, log sampling, demos and physical site walks. Major non-conformities must be closed before the certificate is issued; minor non-conformities are accepted as an action plan with a deadline. After a successful Stage 2, the certification body issues a three-year certificate. Artefact: certification report and ISO/IEC 27001:2022 certificate.
A typical mistake in year one: discipline relaxes once the certificate arrives. Surveillance audits in years 1 and 2 are strict, without continued PDCA discipline you risk suspension of the certificate. Plan year one post-certification with the same capacity as the build-up year.
How SIDD supports you
SIDD takes SMEs and mid-market companies pragmatically through the twelve steps, either as a full ISO 27001 implementation or as modular coaching, where you have internal security capability but want to add methodology and experience. For the operational ISO officer role we can provide an external CISO or information security officer who owns risk methodology, internal audit, management review and the audit accompaniment.
Operationally we typically complement the implementation with vulnerability scans and penetration tests as evidence for Annex A.8.8, and with IT security workshops as awareness building blocks. For an initial maturity baseline of your current state, reach us via the contact form. If you already know scope and certification target, request an offer, we deliver a fixed-price proposal including a 12-month roadmap within five working days.
