Skip to content

ISO/IEC 27001 · Working level

From the standard's requirement to defensible evidence.

Free templates and clear working steps for teams that want to run an ISMS, not just describe it.

Articles
8
Check questions
20
Templates
6
Chapters
7

Source-based orientation

Articles

  1. 01FundamentalsISO 27001:2022: what an ISMS actually has to deliverThe standard does not demand a museum of documents. It demands a steerable system for information risks, responsibilities and improvement.7 min
  2. 02ScopeDefining the ISMS scope: narrow enough to start, complete enough for the auditA scope is not a marketing phrase. It has to delimit services, organisational units, sites, technology and interfaces consistently.8 min
  3. 03RiskISO 27001 risk assessment without false precisionA usable method connects business impact, scenarios and decisions. A colourful score alone is not yet risk management.9 min
  4. 04ControlsStatement of Applicability: how the SoA becomes a steering documentThe SoA connects risks, selected controls, justifications and implementation status. It is more than a ticked-off Annex A list.8 min
  5. 05ControlsStructuring the 93 controls of ISO 27002 sensiblyOrganisational, people, physical and technological: the four themes help with responsibility and evidence management.7 min
  6. 06AuditPlanning an internal ISO 27001 audit that finds more than missing documentsA good audit follows requirements into decisions, samples and actual operational evidence.8 min
  7. 07GovernanceManagement review: which decisions leadership really has to makeThe management review is not a status presentation. It is meant to decide on changes, performance, resources and improvements.7 min
  8. 08ImplementationImplementing ISO 27001: a realistic order for the startScope, governance and risk method first. After that, controls, evidence and audits can be built without parallel worlds.9 min

How it connects

27000 family

27001
ISMS requirementsCore standard
The certifiable requirements for building, operating and improving an ISMS.
27002
Information security controlsControl guidance
Implementation guidance and attributes for the 93 controls of Annex A.
27003
ISMS implementationImplementation
Supplementary orientation for planning and building the management system.
27004
Measurement and evaluationEffectiveness
Guidelines for monitoring, metrics, analysis and evaluation.
27005
Information security risksRisk
In-depth guidance on identifying, assessing and treating risks.
27007
ISMS auditingAudit
Guidelines for audit programmes and for conducting ISMS audits.
27017
Cloud controlsCloud
Supplementary information security controls for cloud services.
27035
Incident managementIncidents
Processes and principles for handling security incidents.

From knowledge into operation

Do not lose the results in yet another file.

KaitoSec connects requirements, owners, risks, controls and evidence in one working model.

Independent working aid by KaitoSec GmbH. No ISO publication and no substitute for the original standard text or for certification consulting.

Content as of: 21 July 2026