Implementation
Implementing ISO 27001: a realistic order for the start
Scope, governance and risk method first. After that, controls, evidence and audits can be built without parallel worlds.
9 minute read · Content as of 21.07.2026
Start with decisions, not with 93 individual projects
A sustainable build starts with mandate, scope, roles, context and risk criteria. Without these foundations, controls and documents end up with contradictory priorities.
Build evidence into operations
Evidence should be a by-product of a working process. A joiner-mover-leaver process, for example, produces approvals and revocation evidence automatically instead of reconstructing them shortly before the audit.
- Phase 1: scope, context and governance
- Phase 2: assets, risks and treatment
- Phase 3: controls, processes and evidence
- Phase 4: measurement, audit and management review
- Phase 5: corrections and certification readiness
The implementation path makes dependencies visible
In the free path, the work products are ordered by the clauses of the standard. It does not replace a project plan, but it delivers a robust order for the backlog and the handover of responsibility.
Sources used
- ISO/IEC 27001:2022 · ISO · 2022 + Amd 1:2024
- ISO/IEC 27002:2022 · ISO · 2022
- ISO/IEC 27005:2022 · ISO · 2022
- ISMS practice patterns · KaitoSec