ISOStandard

The advisors have many years of experience with the implementation of ISO 27001. They are happy to share some of these tips.

Tip 1: Start at the beginning

It sounds like a clincher, but in practice we sometimes see things go wrong: a good start is half the battle. An ISO 27001 implementation process starts with a good context analysis, in which you determine the scope of the project.

Tip 2: Use a tool

To keep an overview of the process, it helps to use a tool. This can be an innovative software program, but a simple Excel sheet can also suffice. The most important condition is that the tool suits your organization and that the tool helps your organization manage the risks, link measures, and manage documents (including version control!).

Tip 3: Make sure everyone is informed

Information security is everyone's business; not just from the security officer or the project manager. It is therefore important that everyone in the organization is well informed about the working methods and that key figures within the organization are able to explain how the organization deals with points for improvement. Actively involve the management in the assessment; they too are interviewed as stakeholders by the auditor and must have sufficient knowledge and experience to be able to explain the choices made.

Tip4: Obtaining ISO certification is a starting point

Your organization is a 'sworn student'. The process must then continue, otherwise, threats will not be dealt with in a timely manner.