AGIDAT – Datenschutz | Informationssicherheit

ISMS Implementation

Building a structured Information Security Management System — from risk assessment to certification readiness.

What is an ISMS?

An Information Security Management System (ISMS) is a systematic approach to managing information security within an organization. It comprises processes, policies, responsibilities, and measures that together ensure information is appropriately protected.

The internationally recognized standard for an ISMS is ISO/IEC 27001. Companies certified to this standard can present customers, partners, and regulators with independently verified evidence of their information security.

Why build an ISMS?

Customer requirements

More and more clients — particularly in B2B software, healthcare, and critical infrastructure — require their suppliers to hold ISO 27001 certification. Without a certificate, these contracts are simply out of reach.

Regulatory requirements

The European regulatory framework (NIS2, DORA, data protection requirements) increasingly demands demonstrable information security. An ISMS is the most structured answer to that demand.

Protection against real risks

Cyberattacks hit SMEs harder than large enterprises — proportionally, the damage is often existential. An ISMS systematically reduces the risk of attack.

Competitive advantage

ISO 27001 certification is a measurable differentiator in sales — especially against competitors without certification.

The implementation process

Phase 1: Context and scope

Before anything is documented, you need clarity: what exactly should the ISMS cover? Which systems, processes, and locations fall within scope? Who are the relevant stakeholders?

A scope that's too broad makes the project expensive and drawn out. One that's too narrow misses the point. We help you find the right cut.

Phase 2: Risk assessment

The core of every ISMS under ISO 27001 is the risk assessment: what threats exist to your information assets? What is their likelihood and impact?

The result is a risk register and a risk treatment plan: for each identified risk, a decision is made whether to treat it (measure), transfer it (insurance), tolerate it, or avoid it.

Phase 3: Building documentation

ISO 27001 requires a set of mandatory documents:

  • ISMS scope and applicability
  • Information security policy
  • Risk assessment and treatment procedure
  • Statement of Applicability (SoA)
  • Risk register and treatment plan
  • Security objectives and measurement
  • Evidence of competence and training
  • Internal audit reports
  • Management review records

Phase 4: Implementing controls (Annex A)

ISO 27001 lists 93 possible security controls across various categories in Annex A. Not all are relevant to every organization — in the Statement of Applicability, you justify which controls you apply and which you don't.

Typical controls for SMEs include: access control, cryptography, physical security, incident management, business continuity, and supplier security.

Phase 5: Measurement, monitoring, improvement

An ISMS thrives on continual improvement (the PDCA cycle). Regular internal audits check compliance. The management review assesses effectiveness and sets new objectives.

Phase 6: Certification audit

The certification audit is conducted by an accredited certification body. It takes place in two stages: documentation review (Stage 1) and implementation review (Stage 2). Upon success, the certificate is valid for 3 years, with annual surveillance audits.

Timeframe and cost

For an SME, we typically plan for 6–18 months from project start to certification, depending on the size of the scope and available internal resources.

Costs consist of external consulting, internal staff time, and the certification body's fees. We're happy to provide a realistic cost estimate during an initial consultation.

Our promise

We build ISMS programs that are certification-ready — and that genuinely live in day-to-day work. An ISMS that exists only on paper passes no audit and protects you from nothing.