ISO/IEC 27001 · Working level
From the standard's requirement to defensible evidence.
Free templates and clear working steps for teams that want to run an ISMS, not just describe it.
- Articles
- 8
- Check questions
- 20
- Templates
- 6
- Chapters
- 7
Start from the work product
Read no more than the next step needs.
Source-based orientation
Articles
- 01FundamentalsISO 27001:2022: what an ISMS actually has to deliverThe standard does not demand a museum of documents. It demands a steerable system for information risks, responsibilities and improvement.7 min
- 02ScopeDefining the ISMS scope: narrow enough to start, complete enough for the auditA scope is not a marketing phrase. It has to delimit services, organisational units, sites, technology and interfaces consistently.8 min
- 03RiskISO 27001 risk assessment without false precisionA usable method connects business impact, scenarios and decisions. A colourful score alone is not yet risk management.9 min
- 04ControlsStatement of Applicability: how the SoA becomes a steering documentThe SoA connects risks, selected controls, justifications and implementation status. It is more than a ticked-off Annex A list.8 min
- 05ControlsStructuring the 93 controls of ISO 27002 sensiblyOrganisational, people, physical and technological: the four themes help with responsibility and evidence management.7 min
- 06AuditPlanning an internal ISO 27001 audit that finds more than missing documentsA good audit follows requirements into decisions, samples and actual operational evidence.8 min
- 07GovernanceManagement review: which decisions leadership really has to makeThe management review is not a status presentation. It is meant to decide on changes, performance, resources and improvements.7 min
- 08ImplementationImplementing ISO 27001: a realistic order for the startScope, governance and risk method first. After that, controls, evidence and audits can be built without parallel worlds.9 min
How it connects
27000 family
- 27001
- ISMS requirementsCore standard
- The certifiable requirements for building, operating and improving an ISMS.
- 27002
- Information security controlsControl guidance
- Implementation guidance and attributes for the 93 controls of Annex A.
- 27003
- ISMS implementationImplementation
- Supplementary orientation for planning and building the management system.
- 27004
- Measurement and evaluationEffectiveness
- Guidelines for monitoring, metrics, analysis and evaluation.
- 27005
- Information security risksRisk
- In-depth guidance on identifying, assessing and treating risks.
- 27007
- ISMS auditingAudit
- Guidelines for audit programmes and for conducting ISMS audits.
- 27017
- Cloud controlsCloud
- Supplementary information security controls for cloud services.
- 27035
- Incident managementIncidents
- Processes and principles for handling security incidents.
From knowledge into operation
Do not lose the results in yet another file.
KaitoSec connects requirements, owners, risks, controls and evidence in one working model.
Independent working aid by KaitoSec GmbH. No ISO publication and no substitute for the original standard text or for certification consulting.
Content as of: 21 July 2026