Skip to content

Implementation

Implementing ISO 27001: a realistic order for the start

Scope, governance and risk method first. After that, controls, evidence and audits can be built without parallel worlds.

Back to ISO 27001

9 minute read · Content as of 21.07.2026

Start with decisions, not with 93 individual projects

A sustainable build starts with mandate, scope, roles, context and risk criteria. Without these foundations, controls and documents end up with contradictory priorities.

Build evidence into operations

Evidence should be a by-product of a working process. A joiner-mover-leaver process, for example, produces approvals and revocation evidence automatically instead of reconstructing them shortly before the audit.

  • Phase 1: scope, context and governance
  • Phase 2: assets, risks and treatment
  • Phase 3: controls, processes and evidence
  • Phase 4: measurement, audit and management review
  • Phase 5: corrections and certification readiness

The implementation path makes dependencies visible

In the free path, the work products are ordered by the clauses of the standard. It does not replace a project plan, but it delivers a robust order for the backlog and the handover of responsibility.

Sources used

Back to ISO 27001